What Happened
A dark web listing calling itself Nexus offered digital scans of more than 153 million driver’s licenses this week, alongside 10 million ID cards, 1.9 million travel documents, and smaller batches of medical cards, residence cards, and employment authorization records. Independent analysis from Krebs on Security traced timestamp and device metadata in sample license images to infrared and ultraviolet scanning equipment used at rental car counters and cannabis dispensaries, pointing to Louisiana-based identity verification vendor IDScan.net as the likely source. The FBI’s New Orleans field office opened a formal inquiry into the origin of the data. IDScan.net has not confirmed a breach at time of publication, and the exact number of Canadian records inside the archive remains undisclosed.
Why This Matters for Canadian Organizations
IDScan.net markets scanning hardware and software to retailers, car rental agencies, cannabis dispensaries, and hospitality operators across North America, and Canadian outlets of US rental car and retail chains commonly run the same equipment at the counter. A driver’s license scan carries a full name, date of birth, address, license number, and photograph in one image, information supporting account takeover, synthetic identity fraud, and physical impersonation well beyond what a stolen password enables. The Office of the Privacy Commissioner of Canada treats driver’s license numbers as sensitive identifiers under PIPEDA, and a Canadian business relying on IDScan.net hardware carries notification obligations once scope confirms Canadian records inside the leak. Federally regulated institutions with identity-verification vendors in their onboarding chain should treat this incident as a live test of the third-party risk controls OSFI B-13 expects them to maintain.
What to Do
Canadian retailers, rental agencies, and hospitality operators using IDScan.net equipment should contact the vendor directly to confirm whether their location’s scan data sits inside the leaked archive, rather than waiting on a vendor notification. Privacy and security teams should review contracts with identity-verification vendors for breach notification timelines, data retention limits, and audit rights, and confirm scanned license images are not retained locally on point-of-sale hardware longer than necessary. Individuals who have had a license scanned at a rental counter or dispensary in recent years should monitor credit files and watch for unfamiliar account openings, since a full license image gives fraudsters everything needed to pass identity checks at other institutions. Full details are available from Krebs on Security.






