Employer / Organisation
Sector
Approx. timing (public disclosure)
What happened
Canada Life (The Canada Life Assurance Company)
Insurance; group benefits and retirement
April 2026
Criminal group ShinyHunters accessed certain applications through a Canada Life employee account, exposing personal information for up to 70,000 people, with most affected belonging to one large corporate group benefits client.
Telus / Telus Digital
Telecommunications; digital services
March 2026
Telus Digital confirmed a breach after ShinyHunters claimed a large‑scale theft of data following a multi‑month intrusion; Telus said a limited number of systems were accessed without authorisation.
Loblaw Companies Limited
Retail (food, pharmacy, financial services)
March 2026
Loblaw reported that a criminal third party accessed “basic customer information” such as names, phone numbers and e‑mail addresses after suspicious activity was detected on a non‑critical IT system; passwords, health and payment data were not affected.
Freedom Mobile (owned by Vidéotron)
Wireless telecommunications
December 2025
Attackers used a subcontractor’s compromised account to access data in Freedom Mobile’s account management platform, exposing personal details (names, addresses, dates of birth, phone numbers and account numbers) for a limited number of customers; payment details and passwords were not taken.
Canada Computers & Electronics
Retail (technology, electronics)
February 2026
A system supporting the retailer’s website was breached, affecting customers who checked out as guests between late December 2025 and late January 2026; stolen data included personal details and credit‑card information used in those transactions.
Canadian Investment Regulatory Organization (CIRO)
Financial regulation; quasi‑public employer
January 2026
A phishing‑originated breach first detected in August 2025 was disclosed as far more extensive than initially believed, compromising personal and financial data for about 750,000 investors, including highly sensitive identifiers and account statements.
Earlier this year, the Office of the Information and Privacy Commissioner for British Columbia (OIPC) said that 36 health‑care workers across three B.C. health authorities improperly accessed the medical records of Lapu Lapu Day Festival victims 71 times. According to Lyndsay Wasser, partner and co-chair of privacy and data protection at McMillan, employee snooping is not a niche issue confined to high-profile scandals. It is, in her words, “actually a fairly common problem.”