IDScan.net Data Breach: What Canadians Should Do If Their Driver's Licence Scan Leaked

Reviewed by IT Cares technicians · Updated October 1, 2026

Smartphone and a blank card beside a closed padlock, representing a leaked driver's licence scan and identity protection in Canada
A scanned licence cannot be changed like a password, so the defence is monitoring and blocking misuse.

Quick fix (5 actions today)

  1. Ask Equifax Canada and TransUnion Canada for a fraud alert and get your free credit reports.
  2. Call your mobile carrier and add a port-out PIN to block SIM swaps.
  3. Turn on transaction alerts in your banking apps.
  4. Change any password you reuse, starting with email, and turn on two-step verification.
  5. Ignore every message about this breach that asks you to click, log in or pay. See the full 10-step plan.

What happened at IDScan.net

On September 21, 2026, the Privacy Commissioner of Canada announced an investigation into IDScan.net after an unauthorized third party gained access to the company's systems and stole personal information, including digital scans of driver's licences and other government-issued identification. The investigation is being led under the federal private-sector privacy law, PIPEDA. IDScan.net is a service used by hospitality and nightlife venues to check the identification of customers at the door.

That is the part we can state with confidence, because it comes from the Office of the Privacy Commissioner (OPC) news release, which we opened and read for this guide. According to that release, the Commissioner will examine the security safeguards IDScan.net had in place at the time of the breach, and also whether the company's notifications to affected people were adequate. The OPC says it is engaging with the company so that it takes the steps needed to address the incident and reduce risk to Canadians. It also says it cannot share more while the investigation is active.

Two things are worth noticing in what the release does not say. It does not give a number of victims. And it does not give personal advice to individuals, such as "do this today". That gap is the reason this guide exists. People who were scanned at a bar, a club or a restaurant over the past few years are now asking whether they are exposed and what they should do about it, and the official announcement is written for regulators, not for the person standing at the door last Saturday night.

A word about how we wrote this. Where we read a primary source, we say so. Where we are relying on general, well-established fraud-prevention practice, or on details we could not confirm on an official page, we say that too, and we list those items at the end under our sources. If you see a claim in this article stated as fact, it is either from the OPC release or it is a basic, stable feature of how identity fraud works. Everything else is hedged on purpose.

If you only want the action list, jump to the 10-step plan. If you want to understand the situation first, keep reading, because knowing what is confirmed and what is rumor will keep you from wasting money on the wrong things.

What is known and what is still unknown

Confirmed so far: a breach happened, driver's licence scans were among the stolen data, and the Privacy Commissioner is investigating. Not confirmed: how many people are affected, which exact fields were taken for each person, and whether any of the data has been used for fraud. The table below separates the two so you can see where the solid ground ends.

QuestionStatusWhat we can say
Was there a breach at IDScan.net?Confirmed (OPC release)An unauthorized third party stole personal information from the company.
Were driver's licence scans taken?Confirmed (OPC release)The release says the data included digital scans of driver's licences and other government-issued ID.
Is there a regulator investigation?ConfirmedAnnounced September 21, 2026, under PIPEDA.
How many people are affected?Not publishedThe OPC release gives no victim count.
Is the 153 million figure true?Unverified claimReported by Cybernews as what a seller claims. Not a confirmed number of victims.
Is my own scan in the data?UnknownNo official public lookup was verified. Assume it is possible if a venue scanned your ID.
Is the data being used for fraud?UnknownPossible in principle. No confirmed cases were found in the sources we read.
Will I be notified?UnclearThe OPC is reviewing the adequacy of notifications. Do not wait for one.

The pattern is familiar from other breaches. A headline arrives with a big number, a company publishes an advisory, a regulator opens a file, and then months of silence follow while the facts are established. During that silence, the most useful thing you can do is shift from asking "was I in it?" to asking "what is the worst thing someone could do with my details, and have I made that hard?" That second question you can answer today, and the answer does not change whether the real victim count is ten thousand or ten million.

It also helps to separate three kinds of exposure. The first is the image itself: the photo of your card, which shows your face, name, address, date of birth and licence number. The second is the data extracted from that image, which some scanning systems store as structured fields so a venue can search or flag people. The third is the metadata: which venue you were at and when. We do not know from the OPC release which of these were present for which people, so the safest assumption for planning is that a scan could contain everything printed on the front of your licence, and possibly the barcode on the back, which usually encodes similar information.

The 153 million figure: a seller claim, not a confirmed victim count

The number 153 million has circulated because Cybernews reported that a seller was offering a huge set of licence data and claimed that scale, but a seller's advertisement is not evidence of how many individuals were harmed, and neither the OPC release nor any source we could read confirms it. We were not able to open the Cybernews article itself (the page refused our request), so we know of that report only from our research notes, and we are treating it as an unverified claim rather than a fact.

There are several reasons to be cautious about a headline figure like this one, none of which require assuming that anyone is lying.

What this means for you in practice: do not panic because of the size of the number, and do not relax because of its uncertainty. Whether you are one of 5 million or one of 153 million, the actions that protect you are the same. A small number does not make your own risk smaller if you are in the set, and a large unverified number does not mean you are in the set.

How to talk about the number

If you share this story with friends or family, say "a seller reportedly claimed 153 million records, which is unverified." Repeating the figure as a fact spreads confusion and makes it easier for scammers to build urgent, frightening messages around it.

Who uses ID scanners, and how your licence ends up in a system

ID scanners are used at venues such as bars and nightclubs to confirm age and sometimes to record visits, and a scan may capture an image of your card and the information on it. If you handed your licence to a doorperson who put it on a device, that is the scenario to think about. If you only showed your card and it was glanced at, it was probably not stored, though we cannot say how every venue operates.

Why would a venue keep the data at all? The reasons vary. Some businesses want to keep a record of who entered in case of an incident. Some use shared ban lists so that a person removed from one venue can be flagged at another. Some are required by local rules or insurers to demonstrate that they checked age. Privacy law in Canada generally expects an organization to collect only what it needs for a stated purpose, to keep it only as long as necessary, and to protect it with safeguards that match how sensitive it is. That is exactly the area the Commissioner says the investigation will look at in this case, namely the safeguards in place at the time of the breach.

You are allowed to ask questions. At a venue, you can ask whether your ID will be scanned and whether the image is stored. After the fact, you can email the venue and ask whether it used IDScan.net, what it retained about you, and how to request deletion. Under federal privacy law and, for Quebec organizations, Quebec's private-sector law, individuals can generally ask organizations about the personal information they hold. We cover the Quebec angle in more detail later in this guide, with the caveats that apply.

One more practical point. If you remember being scanned, write down the approximate dates and venue names now, while you remember them. That small list becomes useful later when you contact a venue, a bureau, or the police. Memory fades quickly, and a timeline helps anyone who has to investigate a suspicious account opening.

Am I affected? How to think about it without a lookup tool

We could not verify that any official, trustworthy public tool exists for checking whether your IDScan.net scan was stolen, so the honest answer is that you cannot be sure, and the safest approach is to assume you may be affected if a venue scanned your licence. Be especially careful with any website, text or email that offers to tell you instantly whether your licence is "in the leak". After large breaches, fake checker sites appear within days, and their real purpose is to collect the very details you were worried about.

Here is a practical way to estimate your exposure without a lookup tool.

Your situationLikely exposureWhat to do
Licence was placed on a scanner at a bar or club in recent yearsPossibleFollow the full 10-step plan.
You only showed your licence and it was looked atLowerDo steps 1 to 4 as a precaution and stay alert.
You never visit venues that check IDLow from this incidentLearn the signs of misuse and keep your basic hygiene up.
You received a notice from a venue or IDScan.netTreat as affectedVerify the notice is real, then follow the plan.
You received a message that offers a "check" linkProbably a scamDo not click. Go to official sites by typing the address.

What can you legitimately do to find out more?

  1. Ask the venues you visited. Send a short email to the venue's contact address and ask whether it used IDScan.net, whether your information was held, and whether you were notified. A venue that holds personal information should have a person responsible for privacy.
  2. Watch the official pages. The OPC page is the authoritative source for the investigation. If a notification process or a public advisory is published there, it will be linked from the news release.
  3. Look at your own accounts. The most reliable "test" is not a lookup, it is evidence: check your credit reports, your mobile account, and your email for anything unfamiliar. A clean result today does not prove you are safe, but an unfamiliar item is a clear signal to act.
  4. Use dark web monitoring carefully. Some paid and free services scan for leaked email addresses and passwords. They are useful for credentials, but a scanned image of an ID may not be indexed in them at all. Our dark web monitoring guide explains what these tools can and cannot find.

The mindset to adopt is simple: treat the possibility as real, spend one focused evening on defence, and then move on. The steps in this guide are cheap or free, and almost all of them are things security professionals recommend regardless of any breach.

What a leaked driver's licence actually enables

A leaked licence scan gives a criminal your legal name, home address, date of birth, photo and licence number, which can help them pass weak identity checks, build convincing phishing messages, and pressure a phone carrier into moving your number, but it is rarely enough by itself to take over your bank account. That is an important distinction. A licence is a strong ingredient in identity fraud, not the whole recipe. Criminals combine it with other pieces: a leaked email and password from an older breach, a purchased SIN, a stolen mailing address, or information you posted on social media.

Here are the main ways such a document tends to be misused. These are general patterns of identity fraud, not confirmed findings about this particular breach.

1. Opening accounts in your name

Lenders, phone companies and online services verify you with a mix of personal details. A licence supplies several at once. A criminal might apply for a phone plan, a credit card, a buy-now-pay-later account or a small loan using your name and address with a different mailing address or email. The first sign is often a collection letter months later, which is why a credit report check matters.

2. SIM swapping and number porting

Many accounts send a text code to your phone number as a safety check. If a criminal convinces your carrier to move your number to a SIM they hold, or to port it to another carrier, they receive those codes. To do this they need to sound like you, and details from your licence help. We cover the defence, a port-out PIN, in the action plan. Our guide on smishing also explains how text-based scams work.

3. Credible phishing and social engineering

A message that uses your real name and your real street feels trustworthy. A caller who says "I am calling about your licence ending in 7" sounds official. This is probably the most common real-world outcome: not a dramatic account takeover, but a stream of tailored scam attempts. See what phishing is and the guide on AI-generated phishing emails because modern scams no longer have the spelling mistakes people used to rely on.

4. Fake identity documents

A clear photo and the data on a card can be used as raw material for a counterfeit card or a doctored image for use in an online verification. The quality of modern forgeries varies, and most services use extra checks such as selfie matching, but it is a risk to be aware of and one reason to monitor your accounts.

5. Targeted harassment and physical risk

A licence contains your home address and photo. For most people this is a minor concern, but for people with a stalker, an abusive ex-partner or a public profile, an exposed address can be a safety issue. If that applies to you, treat the leak as a safety matter, not only a financial one, and speak to local police or a support service. Some provinces have address confidentiality programs for people in danger, though we have not verified the details.

What a licence scan does not give

It does not reveal your passwords. It does not by itself give access to your bank. It does not contain your SIN, since Canadian licences do not carry one. It does not mean that anyone has used it. This matters because people often fear the worst and then freeze up. A focused, calm response is more useful than worry.

If you want the broader context for what to do once misuse does happen, our identity theft recovery guide covers the recovery side in detail. This article focuses on the stage before that: reducing your risk now.

Illustration of a shield with a keyhole protecting blank ID card silhouettes from network threats

The 10-step action plan

Do these ten things in roughly this order: fraud alerts, credit reports, mobile account lock, bank alerts, password changes, phishing vigilance, licence replacement questions, SIN protection, a CAFC report if needed, and a firm refusal to pay for breach removal. Steps 1 to 5 take most people one to two hours and deliver most of the protection. Set aside an evening and work through them with a coffee.

A note on accuracy before we start. The instructions below describe how these protections generally work in Canada. We were unable to open the bureau and government pages while writing this, so the exact menu names, fees, phone numbers and processing times may differ from what you see. Always follow the current instructions on the official site, and be wary of search ads: type the bureau's address yourself or use a link from a site you already trust.

Checklist: print or keep open

  • ☐ 1. Fraud alert requested at Equifax Canada
  • ☐ 1. Fraud alert requested at TransUnion Canada
  • ☐ 2. Credit report from both bureaus reviewed
  • ☐ 3. Port-out PIN or number lock set with mobile carrier
  • ☐ 4. Bank and credit card alerts turned on
  • ☐ 5. Reused passwords changed, two-step verification on
  • ☐ 6. Phishing rules shared with family
  • ☐ 7. Questions asked of provincial licence office
  • ☐ 8. SIN protected, not shared casually
  • ☐ 9. Incidents reported to CAFC if any
  • ☐ 10. Decision made to ignore "removal" offers

Step 1: Place fraud alerts at Equifax Canada and TransUnion Canada

Canada has two national credit bureaus, Equifax Canada and TransUnion Canada, and you should contact both to ask for a fraud alert, which tells lenders to take extra steps to verify your identity before extending credit. Lenders do not all report to both bureaus, so an alert at only one leaves a gap.

How it generally works: you contact each bureau through its official website or phone line, prove your identity, and request that a fraud alert be placed on your file. The bureau then adds a flag to your credit report so that creditors see a warning when someone applies in your name. Some lenders will then phone you or ask for extra proof before approving. We could not confirm the current length of an alert, whether it is free in every case, or whether it can be renewed online, so check those details on each bureau's page.

Two points that surprise people. First, a fraud alert is a speed bump, not a wall. It makes approval harder for a thief and gives you a chance to notice, but it does not physically prevent a lender that ignores it. Second, different provinces have different rules for stronger tools, such as a security freeze, and the bureaus describe their own options. If a freeze is available to you, understand how to lift it temporarily before you apply for a mortgage, a car loan or a phone plan, because forgetting this step is the classic way people get stuck at the dealership.

ToolWhat it doesTypical trade-off
Fraud alertFlags your file so lenders verify identityCan add friction to your own applications; verify duration with the bureau
Security freeze (where offered)Restricts access to your fileYou must lift it to apply for credit; fees and rules vary, verify with the bureau
Credit monitoring (paid or free)Notifies you of changes to your fileDetects after the fact; prices vary

Keep a note of the date, the person you spoke to, and any confirmation number. If a bureau asks you to upload a copy of your licence to prove who you are, ask yourself whether you are on its real website, and do so only through a secure page you reached by typing the address.

Step 2: Get and read your credit reports

Request your credit report from both Equifax Canada and TransUnion Canada and read every line for accounts, addresses, employers and inquiries that you do not recognize. In Canada, you are entitled to a free copy of your credit report from each bureau on request, though the free route is often by mail or through a specific form, and online offerings may be paid or subscription-based. We could not verify the current free-access process, so look for the option labelled as a free personal credit report on the bureau's site and avoid signing up for a trial you do not want.

What to look for when you read it:

If you find something, do not argue with the collector first. Contact the bureau and the lender, state in writing that the account is the result of identity fraud, and ask for their fraud department. Keep copies. The next step after that is a report to the CAFC and, where money was lost, to police, as covered in step 9. For the whole recovery process, see our identity theft recovery guide.

Plan to re-check your reports every few months for the next year. Fraud sometimes appears late, because a criminal may wait before using a stolen identity, and the first sign is often a missed-payment notice. Setting a recurring reminder in your calendar costs nothing and is the single best habit you can build.

Step 3: Lock down your mobile account (port-out PIN)

Call your mobile carrier or use its secure app to add a port-out PIN, number lock or account PIN, so that nobody can move your phone number to another SIM or carrier without a code that only you know. This is one of the most valuable steps in the plan, because your phone number is the key to your text-message codes, and a thief who controls it can reset passwords on many other accounts.

Carriers in Canada offer different protections under different names: a port-out PIN, an account PIN, a number lock, a request for in-store ID only, or a passphrase for the account. We did not verify the specific feature names or steps for each carrier, so ask in plain language: "I want to protect my number against SIM swap and porting fraud. What can you add to my account?" Then write down what they set up and confirm you have the PIN stored in your password manager, not in your notes app.

Also do the following:

  1. Review who is authorized on your account and remove anyone you do not recognize.
  2. Turn on notifications for SIM changes, number transfers and account changes, if offered.
  3. Move key accounts off SMS codes where you can. An authenticator app or a passkey is much harder to intercept than a text. Our guide on setting up two-factor authentication and the explainer on passkeys walk you through that.

Warning signs that a SIM swap may be happening: your phone suddenly shows no service for no reason, you stop receiving calls and texts, and you get messages from your carrier about a SIM change you did not request. If that happens, contact your carrier right away from another phone, then your bank. Speed matters, because the window between the swap and the theft is often short.

Step 4: Turn on bank and card alerts

Enable push or text alerts for every transaction, login, payee change and e-transfer in each banking and credit card app, so you see suspicious activity within seconds instead of at the end of the month. Most Canadian banks and card issuers offer configurable alerts, though the menu names differ and we did not verify them for each institution.

A good alert setup includes:

Then do a quick manual review of the last 60 days of statements on every account, including the ones you rarely use. Add a verbal password or security question to your bank profile if the bank supports it, and tell the bank you are worried about identity theft, so that staff are alert to unusual requests, such as a branch visit with an ID matching yours. Banks have their own fraud teams and they are usually more responsive than people expect once you say the words "possible identity theft".

If you see a charge you do not recognize, call the number on the back of your card and do not use a number from a text message or email. Ask for the charge to be disputed and for the card to be replaced.

Step 5: Change reused passwords and turn on two-step verification

Change the password on your main email account first, then on banking, mobile carrier, cloud storage and social accounts, making each one unique, and turn on two-step verification wherever it is offered. A driver's licence leak is not a password leak, but identity thieves combine data sets. If your email and password from some older breach is already in circulation, the details from your licence make it easier to answer "security questions" or to talk a support agent into a reset.

Priority order, because your email is the master key to everything else, since resets go there:

  1. Primary email account (and any recovery email).
  2. Mobile carrier account and your phone's cloud account (Apple or Google).
  3. Banks, credit cards, investment and payment apps.
  4. Government portals such as your tax account or provincial health and licence accounts.
  5. Shopping, delivery and social accounts that store a card or your address.

Use a password manager to create long, random, unique passwords so you do not need to remember them. If you are new to the idea, our password manager guide compares options and explains setup. If you are not sure whether your current passwords are good enough, the password strength self-check guide helps you find the weak ones.

For two-step verification, prefer an authenticator app or a hardware key to text messages, particularly for email and banking, because of the SIM swap risk described above. Save the backup codes in your password manager or in a safe place. If you ever lose access to your authenticator, see our guide on recovering 2FA access.

Finally, check the security questions you may have set up years ago, such as "street you grew up on" or "mother's maiden name". If these answers are printed on your licence or are easy to find, replace them with random strings that you store in the manager. A security question is just another password, and an easily guessed one.

Step 6: Expect phishing and learn the pattern

After any well-publicized breach, scammers send fake "breach notification", "identity protection" and "claim your compensation" messages, so treat every unsolicited message that mentions IDScan.net, your licence or a data leak as suspect, and verify through an official site you reach by typing the address yourself. This is not speculation about this case in particular. It is a repeated pattern: fraudsters follow headlines because worried people click.

Typical lures to expect:

Five rules that stop almost all of these:

  1. Do not click links in unexpected messages. Open the official site by typing the address or using a saved bookmark.
  2. Hang up and call back on a number from the back of your card or an official website.
  3. Never share one-time codes. No real bank, carrier or government agency asks you to read out a code you just received.
  4. Be suspicious of urgency. "Within 24 hours" is a pressure tactic.
  5. Do not move money to a "safe account". This is a hallmark of fraud, not protection.

Scam messages are getting better. With generative AI, a text or email can be fluent, personalized and free of the old giveaways. See our guides on AI-generated phishing emails and what to do after a fake tech support scam if you think you already responded to one.

Realistic scenario: the compensation text

Realistic scenario (illustrative, not a real case): Maya, 29, goes to bars on weekends and hears about the breach. Two days later she gets a text that says she is eligible for a 250 dollar compensation payment and must "confirm identity" on a link. The page asks for her licence photo and her online banking login. Maya does not click. She types her bank's address, sees nothing unusual, and forwards the text to the carrier's spam reporting number. What saved her was the rule that no one gets paid by asking for a bank password.

Step 7: Ask your licence office about replacing the licence

Contact your provincial licence authority and ask whether they recommend replacing your licence or changing its number after a possible leak, because policies vary by province and we could not verify a standard rule, so do not assume that a replacement is automatic, free or possible. Some jurisdictions may flag an identity file, replace a card, or issue a new number in cases of confirmed identity theft. Others treat a leaked scan as insufficient grounds. What applies to you depends on where you live and on whether your identity has been misused.

Questions to ask the office:

Be realistic about what a new card achieves. A replacement card prevents someone from using the old physical card, but a scanned image of the old one may still show the same name, address and birth date, which cannot be changed. If the office gives you a new number, that helps to some degree. If it does not, the monitoring steps in this plan are your main protection.

Only use official government sites and phone numbers for this, and be suspicious of any text that offers a "licence renewal link" or a payment portal. For Quebec, see the Quebec section below.

Step 8: Protect your Social Insurance Number

Your licence does not contain your SIN, so a licence leak alone does not expose it, but you should still limit who sees your SIN, give it only when legally required, and never provide it to someone who contacts you first. The SIN is one of the most sensitive identifiers in Canada, and combined with a name, address and date of birth, it is the piece that completes an identity thief's kit.

Sensible practices:

If you believe your SIN has been misused, contact the relevant government office and the credit bureaus. We did not verify the current Service Canada procedure for this, so check the official Government of Canada site, and treat any alternative number or portal from a text message as a scam. Our identity theft recovery guide also covers what to gather before you call.

Step 9: Report to the Canadian Anti-Fraud Centre (and police if money was lost)

If your identity has been misused, or someone tried to defraud you using details that may have come from this breach, report it to the Canadian Anti-Fraud Centre (CAFC) at 1-888-495-8501 or through its online reporting system, and contact local police if you lost money or documents were used. The CAFC number comes from our research notes on a CAFC alert, and we could not open the CAFC site to confirm it for this article, so check it on the official site before you call.

A report matters even when there is no loss. Fraud agencies use reports to spot campaigns, and a record of your report helps if you later have to prove to a lender that an account was fraudulent. Reporting a scam attempt, such as a fake compensation text, is also useful, because it helps warn other people.

What to prepare before reporting:

  1. A short timeline: when you were scanned, when you noticed something, what happened.
  2. Screenshots of messages, phone numbers, websites and email headers if you have them. Do not forward suspicious attachments to others.
  3. Account numbers and reference numbers for any fraudulent account or charge.
  4. Copies of your credit report pages that show the unfamiliar items.
  5. A log of every call: date, name, company and what was agreed.

Keep a single folder, paper or digital, where all of this lives. People who are organised in the first week typically recover faster, because every institution asks the same questions and you can answer them from the folder.

Step 10: What NOT to do, especially paying for "breach removal"

Do not pay any service that promises to delete your licence scan from the dark web or from criminal forums, because once copied, data cannot be reliably removed by a third party, and "removal" offers are a common follow-on scam after breaches. Real protection is monitoring and blocking misuse, which costs little or nothing.

Other things not to do:

Be careful also about overcorrecting. Some people react by closing all their accounts, buying expensive identity insurance, or moving their savings around in a panic. None of that is needed. Calm, ordered steps beat dramatic ones.

OptionDoes it help?Cost in CAD
Fraud alerts at both bureausYes, reduces fraudulent creditCheck with bureaus; verify fees
Port-out PIN at carrierYes, blocks SIM swap and portingUsually no charge, verify with carrier
Bank and card alertsYes, fast detectionUsually free
Password manager and 2FAYes, strongest everyday defenceFree to a few dollars per month
Paid credit monitoringPartly, detection onlyVaries; verify current prices
"Dark web removal" servicesNo, cannot guarantee deletionNot worth paying

The Quebec angle: SAAQ, Law 25 and the CAI

If you live in Quebec, your licence is issued by the SAAQ, and Quebec's private-sector privacy law, as modernized by Law 25, gives you rights over personal information held by businesses, but we could not verify how these apply to this specific case, so treat what follows as general orientation and confirm with the authorities. The federal OPC is investigating IDScan.net under PIPEDA. Quebec has its own regulator for private-sector privacy, the Commission d'acces a l'information (CAI), and the two can both be relevant when a Quebec venue is involved.

What you can reasonably do:

  1. Ask the venue about your information. Under Quebec law, organizations generally have to be able to tell you what personal information they hold, and you can ask for access and correction. Write to the venue's person in charge of privacy protection. Law 25 requires businesses to designate one, and the contact is usually listed on their site. We did not verify the exact obligations for your situation.
  2. Ask about confidentiality incidents. Law 25 introduced obligations for organizations to handle and record confidentiality incidents and, where there is a risk of serious injury, to notify affected people and the CAI. Whether the legal threshold applies to a given venue is a question for them, and we have not verified how it plays out here.
  3. Contact the SAAQ. Ask what they can do if your licence information may be compromised: a note on your file, a replacement card, or other measures. We did not verify an official SAAQ procedure, so do not assume one exists, and use only the SAAQ's official phone number and website.
  4. If the venue does not answer, consider a complaint to the CAI. The CAI's website explains how to file a complaint and the time frames. We have not checked these details.

The same caution about scams applies strongly in Quebec, where fake messages pretending to be from the SAAQ are a recurring theme. Do not follow links in texts about your licence. Instead, open your official account by typing the address.

If you run a venue or business in Quebec that scans IDs, you have duties too, and this incident is a reminder to look at them. See the section for businesses below.

Three realistic scenarios

The following scenarios are illustrative, not real cases, and show how the plan plays out for different people. Numbers are examples.

Scenario 1: Daniel, 34, Montreal, regular at several bars

Realistic scenario (illustrative): Daniel was scanned at three venues in the last two years. He spends 90 minutes one evening on steps 1 to 5. He requests fraud alerts at both bureaus, orders his reports, sets a port-out PIN with his carrier, enables alerts on two bank accounts and a credit card, and changes his email password to a 20-character random one. Cost: zero dollars. Two weeks later, one report arrives with no unfamiliar items, and he sets a reminder to re-check in three months.

Scenario 2: Priya, 41, Toronto, spots a new phone line

Realistic scenario (illustrative): Priya checks her credit report and finds an inquiry from a phone retailer she never visited and a postpaid line with a 1,400 dollar device financing balance. She contacts the carrier's fraud department in writing, files a CAFC report, disputes the account with the bureau, and keeps a log of reference numbers. The carrier closes the account and removes it from her file after review, which takes several weeks. Her fraud alert had already made the lender call her number on file for verification once.

Scenario 3: Marc, 58, Quebec City, receives a call

Realistic scenario (illustrative): A caller says he is from "the bank's fraud team", knows Marc's address and licence number ending, and asks him to move 8,000 dollars to a safe account. Marc hangs up, calls the number on the back of his card, and learns there is no fraud on his account. He reports the call to the CAFC. The caller had the details but not the one thing that mattered, Marc's willingness to move money on someone else's instructions.

If you run a venue or business that scans IDs

Collect the minimum, keep it for the shortest time you can justify, encrypt it, restrict who can see it, and know in advance who you will call and what you will tell customers if a supplier is breached. The OPC says its investigation is looking at safeguards and notifications, which are the two areas every business that handles ID should be able to defend.

A practical checklist for owners and managers:

If you want a second pair of eyes on your small business setup, such as which devices hold customer data, how your Wi-Fi is segmented and whether your backups are safe, our team can help. See our guide on dark web monitoring for how to detect leaked business credentials.

What this costs in Canadian dollars: DIY versus paying a technician

Doing the steps yourself costs little or nothing in cash, usually 2 to 4 hours of your time over a week, whereas paying a technician to help you harden devices and accounts is optional and, at IT Cares, is the single 119.99 dollar CAD Expert Consultation for 60 minutes. You do not need to buy any protection product to follow this plan.

ItemDIY cost (CAD)TimeNotes
Fraud alerts (2 bureaus)Verify with bureaus30 to 45 minTerms vary; check official pages
Credit reports (2 bureaus)Free route available on request; verify30 minRe-check every few months
Carrier PIN or number lockUsually free; verify15 minStore PIN in a password manager
Bank and card alertsFree20 minDo it in each app
Password managerFree to about a few dollars per month1 to 2 hoursStart with email and banking
Authenticator appFree20 minSave backup codes
Replacement licenceProvincial fee, verifyVariesMay not be needed or allowed
Expert help, 60 minutes119.99 dollars1 hourOptional, remote

The most expensive outcome is not any of these items. It is a fraudulent loan or a drained account that you notice late. By comparison, the preventive steps are inexpensive. Be careful with paid monitoring subscriptions: they can be useful but they mostly tell you after something happens, and prices vary, so compare before subscribing.

A 30-day timeline

Spend today on steps 1 to 5, this week on steps 6 to 8, and set recurring reminders so that you re-check your credit reports and accounts over the next year. A schedule keeps the effort proportional.

WhenDo this
TodayFraud alerts, order credit reports, carrier PIN, bank alerts, email password and 2FA
This weekPassword manager rollout, other passwords, ask venues and licence office your questions, tell family about scam patterns
Day 14Read the credit reports that arrived, dispute anything unfamiliar
Day 30Re-check statements, check the OPC page for updates, review your alert settings
Every 3 months for a yearRe-pull credit reports, review phone account and authorized users

Update the family. Parents and grandparents are favourite scam targets, and one short conversation about "we never move money because someone phoned us" is worth more than any software.

Official resources

The authoritative source for this incident is the Office of the Privacy Commissioner of Canada, and for general fraud reporting and prevention the Canadian Anti-Fraud Centre, the credit bureaus and your provincial licence authority are the right places to go, always reached by typing the address yourself.

When to call a professional

Call a technician if you think a device is compromised, if you responded to a suspicious message, if you cannot recover an account, or if you simply want someone to walk through the steps with you while you do them. A good time to ask for help is right after a scam attempt, when you are unsure which accounts you exposed.

IT Cares has provided remote and on-site IT support in Quebec and across Canada since 2014. We can connect remotely, check your computer and phone for signs of malware or unwanted remote-access tools, help you set up a password manager and authenticator app, and walk you through account recovery. We do not take payment for "removing" data from the dark web, because nobody can honestly promise that. You can book a session or call us at 1 (888) 711-9428. The Expert Consultation is 119.99 dollars CAD for 60 minutes.

We also recommend that you read our identity theft recovery guide and keep the phishing basics handy for the family.

Bottom line

The confirmed facts are limited: IDScan.net was breached, licence scans were among the stolen data, and the Privacy Commissioner is investigating, while the 153 million figure remains an unverified seller claim. You cannot control what already left the building, but you can make the stolen data much harder to use. Place the alerts, read your reports, lock your phone number, switch on bank alerts, clean up your passwords, ignore the inevitable scam messages, and report what you find. Then check back on the OPC page for updates as the investigation proceeds.

Still stuck? Get a technician on it now

Remote support from IT Cares: we connect to your device, fix it with you watching, and explain what happened.

Frequently asked questions

What is the IDScan.net data breach?
According to a September 21, 2026 news release from the Office of the Privacy Commissioner of Canada, an unauthorized third party accessed IDScan.net systems and stole personal information, including digital scans of driver's licences and other government-issued ID. The OPC says it is investigating IDScan.net's security safeguards and the adequacy of its notifications under PIPEDA. The release does not give a victim count.
Did 153 million people have their licence leaked?
Not confirmed. The 153 million figure is a claim attributed to the seller of the data and reported by Cybernews. It has not been verified by the Privacy Commissioner or confirmed as a count of individual victims. Treat it as an unverified claim and avoid repeating it as fact.
How do I know if my licence scan was in the breach?
I could not verify that an official public lookup tool exists, so do not trust sites that promise instant results, as many are phishing traps. The practical approach is to assume exposure if a venue scanned your ID and wait for a direct notice from the venue or IDScan.net. Contact the venue's privacy officer to ask.
Why do bars and clubs scan IDs?
Many hospitality venues use scanners to check age and keep out banned patrons. Some services keep the scanned image or extracted fields in a database. How long data is retained varies by operator, and you can ask a venue what it keeps and for how long.
What can a criminal do with my driver's licence scan?
A licence carries your name, address, date of birth, photo and licence number. Combined with other leaked data it can help criminals pass identity checks, open accounts, attempt a SIM swap with a carrier, or make phishing messages convincing. Having a scan alone does not mean they succeed, which is why layered protection works.
Should I freeze my credit in Canada?
Canadian bureaus offer fraud alerts, and some provinces and bureaus offer additional security freeze options with differing rules and fees. I could not verify current terms on bureau pages, so check Equifax Canada and TransUnion Canada directly for what applies in your province before deciding.
Can I get a new driver's licence number?
That depends on your province and the circumstances. Some authorities may allow replacement or a new number after identity theft, others may not. Contact your provincial licence office (SAAQ in Quebec) and ask what they offer. I could not verify a standard policy, so treat any promise of a guaranteed new number as unconfirmed.
Is a fraud alert the same as a credit freeze?
No. A fraud alert asks lenders to take extra steps to verify your identity before approving credit. A freeze restricts access to your file. Rules, fees and availability differ by bureau and province, so confirm details with Equifax Canada and TransUnion Canada.
What is a SIM swap and why does a licence matter?
A SIM swap is when a criminal convinces your carrier to move your number to a SIM they control, so they receive your text codes. Licence details can be used as identity proof in these attempts. A port-out PIN or number lock with your carrier reduces the risk.
Will I get a notification?
The OPC says it is looking at the adequacy of IDScan.net's notifications, and the company reportedly issued a public advisory earlier in September. Whether you personally receive a notice depends on the venue and the data held, so do not wait for one before protecting yourself.
Should I pay a service to remove my data from the dark web?
No. Once data is copied it cannot be reliably deleted by a third party, and 'removal' services are a common scam after breaches. Spend the time on fraud alerts, credit checks and account hardening, which actually reduce harm.
Who do I report identity fraud to in Canada?
Report to the Canadian Anti-Fraud Centre (phone 1-888-495-8501) and to local police if you lost money or documents were misused. Also tell your bank, your carrier and the credit bureaus. Keep a written log of every call and reference number.
Does Quebec law give me extra rights?
Quebec's private-sector privacy law, modernized by Law 25, gives residents rights such as access and correction, and organizations must handle confidentiality incidents. I could not verify the exact obligations in this specific case, so contact the venue's privacy officer and, if unanswered, consider the Commission d'acces a l'information (CAI).

Sources and official references

Last verified: October 1, 2026

Need Help?