Skip to content

It happened to firms like yours.

Real incidents at Canadian firms and organisations — what failed, what it cost, and how long nobody noticed.

Every case is drawn from a primary document — a regulator's published decision or the organisation's own reports. We don't name the firms; the evidence behind every claim is linked inside each case.

a health clinic · Ontario · October 2023
Ontario IPC case note

Ransomware at a shared IT provider put patient records on the dark web.

6 organisations reached through one shared IT provider

Five hospitals and one small clinic bought IT from the same provider. The regulator found the clinic's contract was missing security clauses the hospitals' agreement carried.

Missing control: Privileged account management on administrator accounts, including MFA

Source: IPC Case of Note, PHIPA Decision 284 Read the case →

a registered psychologist’s practice · Alberta · March 2021
Alberta OIPC decision

One phishing email took over the mailbox. The patients had to be told.

207 patients the practice was ordered to notify

Someone at a one-practitioner psychology practice answered an email that looked like it came from Microsoft. Days later the mailbox belonged to somebody else, and every contact in it received a request to buy gift cards.

Missing control: Two-factor authentication, added afterwards and only on “most” accounts

Source: Decision P2022-ND-015 Read the case →

a sole-practitioner law firm · Alberta · December 2019
Alberta OIPC decision

The firm’s hard drive was stolen from its IT provider’s vehicle.

150 people whose files left in a third party’s vehicle

A desktop failed. The firm's IT provider took the hard drive away to see what could be recovered — and it was stolen out of the provider's vehicle before anyone had thought about what was on it.

Missing control: Nothing recorded — including whether the drive was encrypted

Source: Decision P2020-ND-137 Read the case →

a law firm · Alberta · November 2019
Alberta OIPC decision

Fraud went out from the firm’s own email while the employee was on vacation.

≈400 people the firm was ordered to notify, after mail went out in its name

Mail went out from a law firm's own address while the employee who owned it was away. They found out when another law firm contacted them about a suspicious message.

Missing control: Nothing stopping the firm’s own address being used, and no way to notice it

Source: Decision P2020-ND-033 Read the case →

a national health-profession association · Canada · October 2019
Alberta OIPC decision

They paid the invoice — to a criminal impersonating their supplier.

Gone paid to a criminal who had spent weeks inside their mailboxes

Somebody was reading two staff mailboxes for weeks. When the real supplier asked where its payment was, the organisation found out it had already wired the money to the person impersonating them.

Missing control: Multi-factor authentication and staff training — both bought afterwards

Source: Decision P2020-ND-048 Read the case →

a real-estate law practice · Alberta · September 2019
Alberta OIPC decision

A staff mailbox was silently forwarding the firm’s mail to criminals.

6 weeks of incoming mail copied out of the firm before anyone noticed

Every message into a staff mailbox was silently copied out — until a scam email arrived, asking the firm to deposit funds.

Missing control: Nothing watching for a mail-forwarding rule on a staff account

Source: Decision P2021-ND-027 Read the case →

a wealth management firm · Alberta · January 2019
Alberta OIPC decision

One phishing click. The client file has not been recovered.

767 clients exposed — with their account numbers and assets under management

A phishing email went to the whole firm. One person opened it, and the attacker took the client contact file — names, social insurance numbers, account numbers, and how much each client had invested.

Missing control: Multi-factor authentication on staff mailboxes

Source: Decision P2019-ND-074 Read the case →

a wealth management firm · Alberta · December 2018
Alberta OIPC decision

The advisor’s own mailbox started sending phishing. A recipient noticed first.

2 months between the click and anybody noticing

An advisor clicked a link in December. Nothing happened. In February the mailbox started sending phishing emails — and the firm found out because one of the recipients told them.

Missing control: Multi-factor authentication on the mailbox, and anything watching it

Source: Decision P2019-ND-099 Read the case →

Which of these could happen to you this month?

No cost, no obligation — you keep the findings either way.

Get your free Security Snapshot