Tuesday, September 22, 2026

Canada Opens IDScan.net Probe Over Stolen Government ID Data

Canada’s federal privacy regulator has opened a formal investigation into IDScan.net, putting the company’s security controls and breach notifications under scrutiny after government-issued identification data was stolen from its systems.

Privacy Commissioner Philippe Dufresne announced the investigation, saying his office will examine whether IDScan.net maintained adequate safeguards and whether its notifications to affected individuals complied with the Personal Information Protection and Electronic Documents Act, or PIPEDA.

The investigation expands the regulatory fallout from a breach involving a company whose core business is verifying high-value identity documents. IDScan.net says its technology performs more than 21 million verifications per month across more than 20,000 locations worldwide, serving industries including hospitality, nightlife, retail, banking, cannabis, and transportation.

McLaren Resources Inc. — sponsored Sponsored · McLaren Resources Inc.

IDScan.net disclosed on September 4 that it learned around September 1 that data may have been accessed without authorization. The company later determined that an unauthorized third party may have accessed or copied information held in customer cloud accounts, including full names and driver’s licence or other government-issued ID numbers. It is offering potentially affected people credit monitoring and identity-protection services.

The publicly confirmed breach scope remains substantially smaller than figures circulating around the incident.

KrebsOnSecurity reported September 1 that a dark-web service called Nexus claimed to hold more than 153 million U.S. and Canadian driver’s licence records, along with millions of other identity documents. Searches reportedly produced about 1.1 million Canadian driver’s licence records, including roughly 473,000 from Ontario.

The FBI previously opened an inquiry into the incident, while the RCMP has said it is monitoring developments.

Canada’s investigation adds a second issue beyond how the data was stolen: how quickly and adequately people were told.

PIPEDA requires organizations to report qualifying breaches and notify affected individuals “as soon as feasible” when the incident creates a real risk of significant harm, which explicitly includes identity theft and financial loss.

Information for this briefing was found via the sources and the companies mentioned. The author has no securities or affiliations related to this organization. Not a recommendation to buy or sell. Always do additional research and consult a professional before purchasing a security. The author holds no licenses.

Leave a Reply

Video Articles

8 Mining Stocks Our Viewers Asked Us to Review | Sept 14th-18th

Canada Is Finally Fast-Tracking New Mines | John Passalacqua – First Phosphate

Gold & Silver Just Added $2 Billion to This Project | Aya Gold – Bourmadine PEA

Recommended

Silver47 Hits 80% Silver, 77% Gold Recovery From Belmont Tailings In Metallurgical Testing

Altamira Gold Lifts Maria Bonita Resource 82% to 1.3 Million Ounces

Related News