Skip to content

Phishing, then ransomware — and the clients’ names, birthdates and SINs were gone.

an accounting practice · Alberta · April 2021. One April morning, an Alberta accounting practice found its servers wouldn't log in. Phishing is believed to have led to ransomware — and the names, dates of birth and social insurance numbers of 1,570 clients went with it.

What happened

Identified in the record as Alberta OIPC Decision P2021-ND-342.

1,570 clients whose names, dates of birth and SINs were taken
Missing control

Two-step authentication on servers — bought immediately afterwards

First page of Decision P2021-ND-342 Alberta OIPC decision Read the original →

On April 2, 2021, the practice found it was unable to log into its own workplace servers. Its investigation concluded that a phishing campaign had led to an attack involving ransomware.

What went with it was the dataset such a practice holds on its clients — names, dates of birth and social insurance numbers, for 1,570 of them.

“It is also reported that the threat actors destroyed copies of the personal information obtained in the attack.”

The Commissioner did not accept that, found a real risk of significant harm, and ordered the practice to notify everyone affected under Alberta's Personal Information Protection Act.

“the possibility that other copies exist cannot be ruled out despite the Organization's belief otherwise.”

The firm's own remediation list reads like the checklist it had lacked: two-step authentication implemented immediately across all servers and programs, and an external firm engaged to run regular security assessments — one week after the clients' numbers were already gone.

The rule that applied — in Alberta

Alberta PIPA s.34.1 and s.37.1 — report the breach, then notify everyone affected

“There is a real risk of significant harm to the individuals affected by this incident. The Organization is required to notify those individuals whose personal information was collected in Alberta pursuant to section 37.1 of the Personal Information Protection Act (PIPA).”

The document

The part that matters

The firm's own conclusion is the argument: two-step authentication on every server, and somebody external running regular security assessments. They bought exactly that — one week after 1,570 clients' social insurance numbers were already gone.

A tax practice holds the one dataset that is worth the most to an identity thief and cannot be reissued: name, date of birth and social insurance number, for every client. The statute differs — Alberta PIPA rather than Ontario's PIPEDA — but the exposure does not, and neither does the reason it happened.

What your own regulator and insurer require →

The documents

We hold dated copies — ask and we will send you what we read.

DocumentOur copy
Decision P2021-ND-342 Copy held 2026-08-20
The firm’s own website Copy held, taken 2026-08-20

The decision itself does not say what the organisation does; it says only “the Organization”. The profession is sourced separately, from the firm's own website, and is cited above.

Could your practice log in tomorrow morning?

No cost, no obligation — you keep the findings either way.

Get your free Security Snapshot

Or see what we check for small accounting practices →