20 Million Canadian Accounts Were Hit by Data Breaches Last Year. Why Is Personal Data Still So Easy to Steal?

20 Million Canadian Accounts Were Hit by Data Breaches Last Year. Why Is Personal Data Still So Easy to Steal?

More than 20 million Canadian accounts were affected by data breaches reported by private-sector organizations in 2025–26, according to the latest annual report from the Office of the Privacy Commissioner of Canada (OPC).

The scale is striking. Businesses submitted 696 breach reports affecting 20,328,495 Canadian accounts during the fiscal year. Combined with breaches reported by federal institutions, the number of affected accounts reached 20,376,654, slightly higher than the previous year’s total.

The number raises an uncomfortable question: after years of investment in cybersecurity, stricter privacy requirements and growing public awareness of cyber threats, why does personal information remain so vulnerable?

Part of the answer may be that attackers do not always need to defeat sophisticated security systems. In many cases, gaining unauthorized access to an account, exploiting an unpatched system or convincing an employee to hand over credentials is enough.

Unauthorized Access Remains the Biggest Problem

Unauthorized access accounted for 78% of all private-sector breaches reported to the OPC under the Personal Information Protection and Electronic Documents Act (PIPEDA) in 2025–26.

Cybersecurity incidents were responsible for 68% of those unauthorized-access breaches. Social engineering accounted for another 13%, while employees misusing their access privileges represented 8%.

These figures illustrate how broad the data breach problem has become. Organizations must protect against external attackers exploiting technical vulnerabilities, criminals using stolen credentials, employees being manipulated through phishing and other social engineering techniques, and threats originating from within their own organizations.

Credential theft is particularly difficult to contain because compromised passwords can continue to circulate long after the breach in which they were originally exposed.

The OPC’s investigation into the 23andMe breach provides a clear example. Attackers used credentials stolen from other websites to access more than 18,000 23andMe accounts through credential stuffing. Because features within the platform allowed users to access information connected to other customers, the breach ultimately affected nearly seven million people globally, including almost 319,000 Canadians.

The investigation concluded that mandatory multi-factor authentication would very likely have prevented the large-scale credential stuffing attack.

For businesses, the lesson extends beyond requiring stronger passwords. Security controls have to account for the reality that some customer credentials are already compromised.

Financial and Telecom Companies Are Being Hit Particularly Hard

Some industries face considerably more breach activity than others.

The financial sector accounted for the largest number of private-sector breach reports in Canada in 2025–26, with 172 incidents, representing 24% of the total.

Telecommunications ranked second with 91 reported breaches, or 15% of the total. Insurance followed with 62 breaches, while services and retail businesses reported 53 and 52 respectively.

The prominence of telecommunications is significant because internet and mobile providers occupy a unique position in consumers’ digital lives. Customers routinely provide telecom companies with names, addresses, contact information, billing details and account credentials, while providers also operate infrastructure through which enormous amounts of communications and internet traffic pass.

“Most consumers choosing an internet provider are understandably focused on things like price, speed and availability. Data security isn’t something the average person is likely to compare between providers, even though these companies can hold a significant amount of personal information about their customers,” says Tomas Novosad, broadband analyst and founder of Home Internet Plans.

The threat to telecommunications infrastructure also extends beyond conventional financially motivated data theft.

The Canadian Centre for Cyber Security has warned that Canadian telecommunications companies are actively being targeted by state-sponsored actors. In one incident disclosed by the Cyber Centre, threat actors associated with the group commonly known as Salt Typhoon compromised three network devices registered to a Canadian telecommunications company.

The attackers exploited a known vulnerability to retrieve configuration files and modified at least one device to establish a tunnel capable of facilitating network traffic collection.

Canadian authorities assess that these actors will almost certainly continue targeting Canadian organizations, including telecommunications providers and their clients.

The Supply Chain Expands the Attack Surface

Protecting an organization’s own network is also no longer enough.

Modern businesses depend on cloud platforms, payment processors, software providers, analytics services, customer support systems and dozens or even hundreds of other vendors. Each relationship can create another potential route to sensitive information.

The OPC has previously highlighted the growing problem of supply-chain attacks, where compromising one service provider can expose information belonging to numerous client organizations.

This creates an asymmetry that strongly favours attackers. A company may invest heavily in protecting its own infrastructure, but its security posture can still depend on the practices of vendors several steps removed from its customers.

One compromised provider can therefore turn what appears to be a relatively isolated cybersecurity incident into a breach affecting organizations and individuals across multiple industries.

Companies Are Collecting More Data Than They Can Afford to Lose

There is another side to the problem that receives less attention: how much information organizations retain in the first place.

Cybersecurity discussions naturally focus on keeping attackers out. But no security system can guarantee that unauthorized access will never occur.

That makes data minimization an important part of breach prevention.

Information that a company does not collect cannot be stolen from its systems. Information deleted when it is no longer required cannot be exposed years later in an unrelated cyberattack.

Under PIPEDA, organizations are expected to use safeguards appropriate to the sensitivity of the personal information they hold. Those protections can include encryption, firewalls, security patches, access restrictions and employee training. The OPC also recommends regularly reviewing safeguards as technology and risks evolve.

Yet the continuing scale of reported breaches suggests that security cannot be treated simply as a compliance exercise.

Organizations need to consider not only whether information is protected, but whether they still need to possess it at all.

A Data Breach Can Follow Consumers for Years

For consumers, the consequences of a breach do not necessarily end when a company patches a vulnerability and sends a notification email.

Passwords can be changed and credit cards replaced. Names, birth dates, addresses and other identifying information are considerably more permanent.

Information obtained from one breach can also become more valuable when combined with information from another. A phone number exposed by one organization, an email address and password obtained elsewhere, and personal details leaked from a third source can collectively create a much more complete profile of an individual.

That information can support convincing phishing attempts, account takeover, identity fraud and social engineering long after the original breach disappears from the news.

The 20 million Canadian accounts affected by private-sector breaches in 2025–26 should therefore be viewed as more than a cybersecurity statistic.

The figure highlights a fundamental challenge facing Canada’s increasingly digital economy: organizations are accumulating enormous quantities of personal information while attackers have more opportunities than ever to reach it.

Preventing every breach may be unrealistic. Reducing the opportunities for attackers, limiting the information available when they succeed and making stolen credentials less useful are much more achievable goals.

For Canadian businesses, that means treating personal data as something that creates risk from the moment it is collected, rather than simply an asset to be stored indefinitely.

And for consumers, the latest numbers are another reminder that trusting a company with personal information increasingly means trusting its cybersecurity practices as well.

 

Staff Writer at CPO Magazine