The Royal Canadian Mounted Police says it is “aware” of an ongoing FBI investigation into a report that hackers gained access to tens of millions of government-issued identity records across North America— including Canadians’ driver’s licences.
Canadians are now being warned to stay vigilant for bad actors that can exploit people’s personal data.
“The RCMP is aware of reports regarding the alleged exposure of driver’s license data. We are monitoring the situation and remain engaged with domestic and international law enforcement and cybersecurity partners as appropriate,” the statement said.
“The RCMP remains committed to investigating reported cybercrime, including breaches of data. However, the RCMP typically does not confirm, deny, or release information relating to investigations until charges are laid and the matter becomes public record. Nor do we comment on investigations led by other police services or authorities in other countries.”
The breach, if confirmed, could be one of the largest-ever exposures of government-issued identity documents in North America, creating risks of identity theft and fraud for tens of millions of people.
What is going on?
The situation, which is still unfolding and which still has numerous unanswered questions, appears to have began on Sept. 1, 2026.
That’s the day that independent journalist Brian Krebs said he had discovered a dark web site selling digital scans of millions of drivers’ licences from people in the U.S. and Canada. He said he confirmed the authenticity of the data being sold with nine people, Reuters reported.
Krebs said he was alerted to the site after it was advertised on a Russian cybercrime forum, with his own driver’s license being offered as a free sample. Krebs said the service, dubbed Nexus, claimed to have tens of millions of licences for people in the U.S. and Canada, as well as millions of other identification cards and travel documents and hundreds of thousands of medical records.
Krebs said that the site appeared to be updating its database of stolen data in real time, indicating that it was being fed by a live breach.
Global News has not independently verified his data and neither the RCMP nor the Canadian Centre for Cyber Security said whether the numbers were accurate, but Krebs pegged the figures at roughly 153 million stolen identity documents from people in the United States and Canada.
In a brief statement on Sept. 2, the U.S. FBI said it was “looking into the incident” but could not comment “due to the ongoing nature of the investigation.”
Get daily National news
The source of the identify documents has not been confirmed by officials but Krebs quoted a representative of New Orleans-based identity verification provider IDScan.net as saying that it was investigating the matter.
Global News has reached out to IDScan.net for comment but has not received a response.
On Sept. 4, IDScan.net had posted a statement saying that on or around Sept. 1, it became aware of data that may have been accessed without authorization.
It then “determined that an unauthorized third party may have accessed and/or copied certain customer information stored within their accounts on the IDScan.net cloud.”
IDScan is a digital identity verification and fraud prevention platform that scans, parses, and authenticates government-issued IDs.
The company did not state the scale of the breach, including how many people may have been affected or from what regions.
However, the report has rapidly triggered fears about the scope and risks, with Krebs saying he discovered high ranking government officials had their data exposed, including Pete Hegseth, the U.S. defence secretary.
Zach Edwards, a threat researcher at the cybersecurity company Infoblox, told Reuters the incident was unprecedented in terms of its sweep.
“There’s never been a breach of driver’s licences at this scale,” said Edwards, who added that his own license was available for sale on the site. Edwards said that the ongoing nature of the breach “means that this attack created legitimate national security risks for high-profile individuals.”
Krebs said the dark web site offering the driver’s license data vanished shortly after he published his report.
What are the risks here?
In its statement, IDScan.net said it believes an unauthorized third party may have accessed and/or copied customer information stored within their accounts on the company’s cloud systems.
This may have included full names, as well as the identification numbers of their driver’s license or other government-issued documents, the company said.
The company adds that full access to this sensitive information required payment, suggesting only a select amount of individuals may have had their data exposed, but is acting with “an abundance of caution” in notifying all potentially impacted individuals.
Those who they believe were impacted are being provided with access to free credit monitoring and identity protection services.
IDScan.net also says it’s cooperating with federal law enforcement on their investigation.
- CPP Investments and Brookfield just launched a $50B Maple Fund. What is it?
- Dollarama expects higher sales as inflation-hit shoppers look for discounts
- Galaxyland’s new Nerf roller-coaster nearly complete at West Edmonton Mall
- What are restrictive covenants and why this Edmonton infill is stirring debate
How stolen identity data can be used
When people’s personal information and data is stolen online, bad actors can engage in identity theft or fraud.
“They say they’re not supposed to keep a copy of it, but we know that’s not always true until there’s a data breach that occurs, and then once it’s out, there’s not much you can do about it — cat’s out of the bag.”
These types of attacks are hard to catch quickly, Cutler says, adding that they raise growing concerns about the security of keeping data in cloud servers.
“It’s called cloud data, it’s where somebody hacks into a cloud, which is a third party provider to the organization. It’s very hard to monitor whenever attacks are occurring up there,” says Cutler.
“Unfortunately, there’s a lot of companies out there that they buy advanced cybersecurity solutions that don’t necessarily monitor the cloud. For example, let’s say their cloud service gets hacked and large amounts of data gets downloaded. Well, most people never get an alert that says, ‘hey, an anonymous large download just happened.'”
Cutler says if these bad actors have people’s information, they can use to it open up bank accounts or other lines of credit, which may sneak up on consumers if they aren’t monitoring their activity.
What else can consumers do?
On top of risks that bad actors can use people’s personal information to engage in financial fraud and identity theft, Cutler says the information can also be shared with others who may contact them posing as someone else to gain additional information or access to accounts and other documents.
This includes phishing or smishing scams, which are fraudulent attempts to contact someone made through email or text message.
“The important thing for the consumers is to watch out for any unsuspecting texts, emails or phone calls that are going to be occurring,” says Cutler.
The Government of Canada’s Centre of Cyber Security urges Canadians to have strong and unique passwords and to never share them with anyone. It also says to be aware of phishing and smishing scams designed to trick users into giving up information by pretending to be a trusted source.
“Always validate the source and make sure you have extra security in place like two-step verification turned on everywhere because if passwords are getting out, they’re going to go after those as well,” says Cutler.
The RCMP also urges Canadians to “remain vigilant.”
“Reports of large-scale compromises involving personal information are concerning,” said the RCMP in the statement.
“The RCMP encourages Canadians to remain vigilant, monitor financial and government accounts for suspicious activity, safeguard personal information, and report suspected fraud to their local police service and the Canadian Anti-Fraud Centre.”
– with files from Reuters
Check this out
I propose a $1 Trillion fine for breach of my data. If agencies, companies, and individuals are held accountable for their failures, perhaps they’ll determine the risk of collecting data is too great, and stop doing it. Problem solved.
DOGE hacked all the info while in advance ahead of the midterms to throw a shadow on the legitimacy of the incoming elections.
Anonymous is a village idiot…..dont be angry anonymous. Remember your a simpleton. Keep it simple…..
This makes me so angry with the Alberta government, making us put heathcare#, citizenship etc. on our licences.
Oh my gosh, this is what people use to prove they can vote.
Leave it to the FBI yet again or Foreign intelligence to spoon feed us intel . Under the corrupt incompetent self serving Liberal Party of Canada our national security has suffered reputation.
Biggest annoying trend in business: companies replacing their call centre navigation with AI.
If you think developers are highly social people, you would be incredibly mistaken. And it shows in their development of AI. It doesn’t listen and provides false information a staggering amount.
Way to lose customers…
Anonymous the village idiot….any article involving the word idiot brings you and your two cents out.
We can confirm and recommend, good job Dudly. Only release statement after some facts became public.
morons at the rcmp are useless, just like the government
Cue the calliope music and the clown car…
Only one of the many hacks, most not reported!
To the person complaining about our health care info being put on driver’s licenses in alberta blame all those albertans who were always complaining about having our health care ID on PAPER instead of laminated or put on plastic. Smith giving those people what THEY WANTED.
And our idiot government thinks we’re going to allow random foreign companies scam our ID.
Get fucked insufferable liberal retards.
Alberta UCP probably sold access to the hackers.
Ah, the collapse of an empire! All empires eventually fall. Economic strain, external threats, social pressures and….TECHNOLOGY! Technology will be the final nail in Canada’s coffin.
I hope I can sue the government for this leak if i get scammed. A class action lawsuit should follow if required. If we cannot trust or government, who can we trust.
Another case example why everyone should push back on any digital implementation of ID’s and sensitive information. Governments continue to show us how horrible they are at safeguarding sensitive information.
F Failed
B Bootlicking
I Inbreds
That about sums it up.
Haha. China must have stolen it. Low IQ White inbreds cant protect their data
And the Alberta UCP think putting our citizenship and health care numbers with our drivers license is a great idea. How wrong can they get?
The FBI are led by a drunk
The RCMP riding the coattails of the FBI yet again