Regulatory Organisation data breach exposed the sensitive data of 750,000 Canadian investors
21/01/2026
The Canadian Investment Regulatory Organisation data breach exposed the sensitive data of 750,000 Canadian investors
The Canadian Investment Regulatory Organisation (CIRO) has confirmed that approximately 750,000 Canadian investors have been affected by a sophisticated phishing attack initially disclosed in August 2025.
The confirmation comes after nine months of forensic investigation and over 9,000 hours of examination by third-party cybersecurity experts and forensic investigators.
The breach exposed sensitive personal and financial information, including dates of birth, phone numbers, annual income, social insurance numbers, government-issued ID numbers, investment account numbers, and account statements.
CIRO emphasised that authentication credentials, such as passwords, security questions, and personal identification numbers (PINs), were not compromised, as the organisation does not collect or store such information in its systems.
CIRO stated that it quickly contained the incident and implemented immediate security measures to secure its systems.
The organisation notified law enforcement, privacy commissioners, and all relevant regulatory authorities upon discovering the breach.
A leading third-party forensic IT investigator was retained to determine the scope and nature of compromised data.
The preliminary investigation revealed that registration information for member firms and registered individuals had been compromised.
CIRO disclosed these findings publicly and directly notified affected members and registrants, and committed to sharing the final results once the e-discovery process concluded.
Protective Measures and Monitoring
Currently, there is no evidence that the exposed information has been misused. CIRO continues active monitoring for malicious activity and has not identified any threat indicators or data exposure on the dark web.
As a precautionary measure, the organisation is providing affected Canadian investors with complimentary credit monitoring and identity theft protection services for 2 years through major credit agencies.
Affected individuals will receive detailed instructions for activating protection services directly from CIRO. The organisation began notification communications on January 14, 2026.
Only some clients and former clients of CIRO dealer members were affected by the cybersecurity incident.
Individuals who did not receive a notification letter but wish to confirm their impact status can request verification through CIRO’s website by submitting a written inquiry using the contact form in the cyber incident section.
Andrew Kriegler, CIRO’s President and Chief Executive Officer, stated: “We are intent on doing right by those who are personally affected.
Matters of privacy and security are significant to us, as are our guiding organisational values of transparency and accountability.”
CIRO remains committed to strengthening its cybersecurity defences and supporting the broader investment industry’s security efforts. Additional information regarding the incident is available on CIRO’s official website.
Source
https://cyberpress.org/ciro-confirms-data-breach/
The Team
Meet the team of industry experts behind Comsure
Find out moreLatest News
Keep up to date with the very latest news from Comsure
Find out moreGallery
View our latest imagery from our news and work
Find out moreContact
Think we can help you and your business? Chat to us today
Get In TouchNews Disclaimer
As well as owning and publishing Comsure's copyrighted works, Comsure wishes to use the copyright-protected works of others. To do so, Comsure is applying for exemptions in the UK copyright law. There are certain very specific situations where Comsure is permitted to do so without seeking permission from the owner. These exemptions are in the copyright sections of the Copyright, Designs and Patents Act 1988 (as amended)[www.gov.UK/government/publications/copyright-acts-and-related-laws]. Many situations allow for Comsure to apply for exemptions. These include 1] Non-commercial research and private study, 2] Criticism, review and reporting of current events, 3] the copying of works in any medium as long as the use is to illustrate a point. 4] no posting is for commercial purposes [payment]. (for a full list of exemptions, please read here www.gov.uk/guidance/exceptions-to-copyright]. Concerning the exceptions, Comsure will acknowledge the work of the source author by providing a link to the source material. Comsure claims no ownership of non-Comsure content. The non-Comsure articles posted on the Comsure website are deemed important, relevant, and newsworthy to a Comsure audience (e.g. regulated financial services and professional firms [DNFSBs]). Comsure does not wish to take any credit for the publication, and the publication can be read in full in its original form if you click the articles link that always accompanies the news item. Also, Comsure does not seek any payment for highlighting these important articles. If you want any article removed, Comsure will automatically do so on a reasonable request if you email info@comsuregroup.com.