Tuor

Security Advisory

153 Million Driver's Licences Leaked. What It Means for Your Business

September 2026 • Toronto

Think about the last time you handed your driver's licence to a rental car counter, a hotel front desk, or a cashier checking your age. Somewhere in that moment a scanner took a picture of it, and a company you have never heard of kept that picture. This month one of those companies was breached, and the fallout is being called the largest exposure of government issued ID in North American history.

153 million driver's licences leaked online

What actually happened

In early September, security journalist Brian Krebs was tipped off to a dark web site called Nexus that was selling searchable scans of more than 153 million driver's licences from the United States and Canada, along with millions of ID cards, travel documents, and medical cards. The seller proved the data was real by offering up Krebs' own Virginia licence as a free sample. On September 4, IDScan.net, a Louisiana based identity verification company that scans and authenticates IDs for retailers, rental agencies, hotels, and cannabis dispensaries, confirmed that an unauthorized third party accessed customer data stored in its cloud platform. The FBI is investigating. The RCMP has said it is monitoring the situation and working with law enforcement partners, and has asked Canadians to stay alert for identity theft and fraud.

A note on the numbers, because we would rather be accurate than dramatic. Of the 153 million licences, roughly 1.1 million appear to be Canadian. That is still more than a million Canadians, and if you have travelled or rented a car in the US in the last few years, you may well be in there too. The Nexus site went dark shortly after the story broke. The data did not. It is still out there, and it will be resold.

Why this one is different

Most breaches leak fields. A name, a number, an email. This one leaked images. Front and back scans of the physical card, and in many cases the ultraviolet and infrared scans used to prove a licence is genuine. That is exactly what a fraudster needs to pass an identity check somewhere else. You can reset a password. You can replace a credit card in a week. Your face, your date of birth, and a high resolution copy of your provincial ID are a much harder thing to take back. The seller also claimed to have been quietly pulling new records for over a year, which means this was not a smash and grab. Someone lived inside that system for a long time before anyone noticed.

The part that matters for your business

Here is the thing we want every business owner to sit with. IDScan.net's customers were not the people whose licences leaked. Its customers were the businesses that installed the scanner. The retailer, the dispensary, the hotel. Their customers trusted them, they trusted a vendor, and the vendor got breached. Now those businesses are the ones facing angry customers and class action lawyers, for a system most of them never thought about after the day it was installed.

You almost certainly have vendors like this. Your payroll platform, your CRM, your booking system, your e signature tool, the app that scans IDs at your front desk. Every one of them is a place your customers' and employees' personal information lives that you do not control. Your security is only as strong as the least careful company in that chain, and under Canadian privacy law the responsibility still points back at you when it goes wrong.

What to do this week

For yourself and your family, keep a closer eye on bank and card statements than usual, and consider a fraud alert or credit freeze with Equifax and TransUnion Canada. Be suspicious of any call, text, or email that references your licence or asks you to verify your identity, because the people holding this data know exactly how to sound legitimate. If a business you dealt with tells you your data was affected, take the free credit monitoring they offer. It costs you nothing and it is the one thing they can actually do for you.

For your business, start with a list. Which vendors hold personal information about your customers or staff, what do they hold, and why. Ask each one where the data is stored, how long they keep it, and whether it is encrypted. Then ask yourself the harder question, which is whether you need to collect it at all. The safest record is the one you never kept. Turn on multi factor authentication for every vendor portal your team logs into, because that is how most of these cloud accounts get taken. And make sure your incident plan covers the scenario where the breach is not yours but you still have to answer for it. That is the scenario every IDScan.net customer is living right now.

Where Tuor stands

We cannot stop a vendor in Louisiana from getting breached, and we will not pretend anyone can. What we can do is help you know which vendors hold what, shrink what they hold, lock down how your team reaches them, and have a plan ready before the phone rings. That is not a product. It is the ordinary, unglamorous work of taking accountability for your clients' data, and it is what our specialists do for Canadian businesses every day. If you want a second set of eyes on your vendor exposure, start with our free cybersecurity assessment, or call 1-833-599-TUOR and ask us where your customers' data actually lives. We will give you the real answer.