{"id":13094,"date":"2026-04-21T13:29:06","date_gmt":"2026-04-21T13:29:06","guid":{"rendered":"https:\/\/www.europesays.com\/canada\/13094\/"},"modified":"2026-04-21T13:29:06","modified_gmt":"2026-04-21T13:29:06","slug":"canada-life-breach-exposes-data-of-up-to-70000-people-mostly-customers","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/canada\/13094\/","title":{"rendered":"Canada Life breach exposes data of up to 70,000 people \u2013 mostly customers"},"content":{"rendered":"<p>&#13;<br \/>\n\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t&#13;<br \/>\n\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Employer \/ Organisation<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Sector<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Approx. timing (public disclosure)<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>What happened<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Canada Life (The Canada Life Assurance Company)<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Insurance; group benefits and retirement<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>April 2026<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Criminal group ShinyHunters accessed certain applications through a Canada Life employee account, exposing personal information for up to 70,000 people, with most affected belonging to one large corporate group benefits client.<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Telus \/ Telus Digital<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Telecommunications; digital services<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>March 2026<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Telus Digital confirmed a breach after ShinyHunters claimed a large\u2011scale theft of data following a multi\u2011month intrusion; Telus said a limited number of systems were accessed without authorisation.<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Loblaw Companies Limited<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Retail (food, pharmacy, financial services)<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>March 2026<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Loblaw reported that a criminal third party accessed \u201cbasic customer information\u201d such as names, phone numbers and e\u2011mail addresses after suspicious activity was detected on a non\u2011critical IT system; passwords, health and payment data were not affected.<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Freedom Mobile (owned by Vid\u00e9otron)<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Wireless telecommunications<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>December 2025<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Attackers used a subcontractor\u2019s compromised account to access data in Freedom Mobile\u2019s account management platform, exposing personal details (names, addresses, dates of birth, phone numbers and account numbers) for a limited number of customers; payment details and passwords were not taken.<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Canada Computers &amp; Electronics<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Retail (technology, electronics)<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>February 2026<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>A system supporting the retailer\u2019s website was breached, affecting customers who checked out as guests between late December 2025 and late January 2026; stolen data included personal details and credit\u2011card information used in those transactions.<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Canadian Investment Regulatory Organization (CIRO)<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>Financial regulation; quasi\u2011public employer<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>January 2026<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t\t&#13;<\/p>\n<p>A phishing\u2011originated breach first detected in August 2025 was disclosed as far more extensive than initially believed, compromising personal and financial data for about 750,000 investors, including highly sensitive identifiers and account statements.<\/p>\n<p>&#13;<br \/>\n\t\t\t&#13;<br \/>\n\t\t&#13;<br \/>\n\t&#13;<\/p>\n<p>Earlier this year, the Office of the Information and Privacy Commissioner for British Columbia (OIPC) said that 36 health\u2011care workers across three B.C. health authorities improperly accessed the medical records of <a href=\"https:\/\/www.hrreporter.com\/news\/hr-news\/egregious-bc-healthcare-workers-caught-snooping-on-lapu-lapu-day-victims-records\/394090\" target=\"_blank\" rel=\"nofollow noopener\">Lapu Lapu Day Festival<\/a> victims 71 times. According to Lyndsay Wasser, partner and co-chair of privacy and data protection at McMillan, <a href=\"https:\/\/www.hrreporter.com\/news\/hr-news\/bc-snooping-scandal-puts-workplace-privacy-and-employer-liability-under-microscope\/394092\" target=\"_blank\" rel=\"nofollow noopener\">employee snooping<\/a> is not a niche issue confined to high-profile scandals. It is, in her words, \u201cactually a fairly common problem.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"&#13; &#13; &#13; &#13; &#13; &#13; &#13; &#13; &#13; &#13; Employer \/ Organisation &#13; &#13; &#13; Sector &#13;&hellip;\n","protected":false},"author":2,"featured_media":13095,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[17,7146,7147,7145],"class_list":["post-13094","post","type-post","status-publish","format-standard","has-post-thumbnail","category-canada","tag-canada","tag-canada-life","tag-cyber-incident","tag-data-breach"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/posts\/13094","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/comments?post=13094"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/posts\/13094\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/media\/13095"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/media?parent=13094"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/categories?post=13094"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/canada\/wp-json\/wp\/v2\/tags?post=13094"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}