The Canadian Centre for Cyber Security responded to 3,216 cyber security incidents affecting federal institutions and Canadian organizations in the 2025-26 fiscal year, up from 2,561 a year earlier and 2,192 the year before that, according to the Communications Security Establishment Canada Annual Report 2025-2026. In 2,282 of those cases, the Cyber Centre identified the incident and notified the organization, rather than the other way around. Over a similar period, the IBM Cost of a Data Breach Report 2026 put the average Canadian data breach at a record CA$7.11 million, and Canadians reported more than $704 million in fraud losses to the Canadian Anti-Fraud Centre for 2025, up from more than $638 million in 2024. Attacks on Canadian organizations are growing in number and in cost, and most of them are never reported to police.
Four forces drive the Canadian numbers in 2026. Ransomware is the top cybercrime threat to Canada's critical infrastructure, and Canadian ransomware incidents known to the Cyber Centre grew by an average of 26 percent a year from 2021 to 2024, according to its Ransomware Threat Outlook 2025 to 2027. Fraud and impersonation dominate what victims report: fraud was the offence in 44,542 of the 90,643 cybercrime incidents police recorded in 2025, per Statistics Canada. Breaches of personal information reached 20,376,654 Canadian accounts across all 1,147 breach reports to the Office of the Privacy Commissioner of Canada in 2025-26, 20,328,495 of them in business reports under PIPEDA, while notices to provincial regulators kept rising. Frontier AI is compressing the time defenders have to respond, in the Cyber Centre's words "in some cases from days or weeks to hours" (Cyber Centre statement, June 2026). The figures below are organized for journalists, researchers, insurers, IT leaders and boards who need a Canadian number with a source they can cite.
This post is the Stingrai research team's canonical 2026 reference for cyber attack statistics in Canada. It assembles more than 200 figures from 11 primary publishers: Statistics Canada, the Communications Security Establishment and its Canadian Centre for Cyber Security, the Canadian Anti-Fraud Centre, the RCMP, the Office of the Privacy Commissioner of Canada, Quebec's Commission d'accès à l'information, the Information and Privacy Commissioner of Ontario, the information and privacy commissioners of Alberta and British Columbia, IBM, and CIRA. Lead data is fiscal 2025-26 and calendar 2025 reporting, the freshest available; Statistics Canada collected its 2025 business cyber survey between January and March 2026 and has not published results as of October 2026, so its business figures are for 2023. Every stat carries its source, year, and methodology window so any claim can be audited inline.
Key statistics at a glance
Cyber incidents handled by the Canadian Centre for Cyber Security (fiscal 2025-26): 3,216, up from 2,561 in 2024-25 (CSE Annual Report 2025-2026).
Average cost of a data breach in Canada (2026 report): CA$7.11 million, the highest level since the study began (IBM Cost of a Data Breach Report 2026).
Fraud losses reported to the Canadian Anti-Fraud Centre (2025): more than $704 million across more than 112,000 reports (CAFC, Top 10 frauds in 2025).
Share of fraud and cybercrime incidents reported (estimate): 5 to 10 percent (RCMP, 6 November 2025).
Police-reported cybercrime incidents (2025): 90,643, or 218.6 per 100,000 people, 5.7 percent below the revised 2024 count of 96,143 (Statistics Canada Table 35-10-0002-01).
Breach reports from businesses to the Privacy Commissioner of Canada (fiscal 2025-26): 696, affecting 20,328,495 Canadian accounts (OPC Annual Report 2025-2026).
Growth in ransomware incidents known to the Cyber Centre (2021 to 2024): 26 percent a year on average (Ransomware Threat Outlook 2025 to 2027).
Spear phishing losses reported to the CAFC (2025): $67.9 million from 571 victims, the second-largest fraud loss category (CAFC).
Canadian businesses impacted by cyber security incidents (2023): 16 percent, while recovery spending doubled to $1.2 billion (Statistics Canada, The Daily, 21 October 2024).
Health privacy breaches reported by Ontario custodians (2025): 12,075, 45 percent of them misdirected faxes (IPC Ontario 2025 Annual Report).
Confidentiality incident notices to Quebec's privacy regulator (fiscal 2024-25): 514, up 16 percent in a year and 559 percent over three years (CAI Rapport annuel 2024-2025).
Online Canadians worried about AI-related cybercrime (January 2026): 73 percent, up from 65 percent in 2024 (Get Cyber Safe Awareness Tracking Survey 2026).
Key takeaways
Incident counts are rising even as a smaller share of businesses report being hit. Statistics Canada found the share of businesses impacted by cyber incidents fell from 21 percent in 2019 to 16 percent in 2023, yet recovery spending doubled to $1.2 billion over two years and the Cyber Centre's incident count rose by about a quarter in a single fiscal year. Fewer businesses are hit, and Statistics Canada suggests the financial consequences of being hit are becoming more severe.
Fraud is the cyber attack Canadians most often report. Fraud accounted for 49 percent of police-reported cybercrime in 2025, and fraud, extortion, identity fraud and identity theft together made up 62 percent. Spear phishing, the CAFC's category for fraudsters impersonating executives, suppliers and clients, cost each victim about $119,000 on average in 2025, the highest of any top-ten fraud type (Stingrai calculation from CAFC figures).
Most attacks never reach police. The RCMP estimates only 5 to 10 percent of fraud and cybercrime incidents are reported, and only 13 percent of Canadian businesses impacted by cyber incidents in 2023 told police. Every Canadian count in this post is a floor.
Ransomware statistics disagree because they measure different populations. Statistics Canada's mandatory survey of businesses with 10 or more employees found 88 percent of 2023 ransomware victims did not pay; CIRA's 2025 survey of 505 cybersecurity decision-makers at organizations with 50 or more employees found 74 percent of victims did. Both describe their own sample accurately, and neither describes the whole economy.
Personal information breaches are mostly cyber-driven unauthorized access. Unauthorized access accounted for 78 percent of PIPEDA breach reports in 2025-26, and 68 percent of those were cybersecurity incidents. Quebec's regulator names cyberattacks, human error and ransomware as the most frequent causes of incident notices, and Alberta's says cyber attacks remain the main cause of private-sector breaches.
Exploitable weaknesses are a growing way in. The share of impacted Canadian businesses hit by attackers exploiting software, hardware or network vulnerabilities rose from 19 to 25 percent between 2021 and 2023, and in June 2026 the Cyber Centre warned that frontier AI lets attackers find and exploit vulnerabilities much faster than before.
Methodology and limitations
Date cutoff: 1 October 2026. Every figure was read from the publisher's own page, table or report during a research pass on that date. The sources, their publication dates and their data windows are:
Statistics Canada: Canadian Survey of Cyber Security and Cybercrime 2023 (released 21 October 2024; reference year 2023; enterprises with 10 or more employees outside public administration; final sample 12,462, response rate 71 percent); police-reported cybercrime Tables 35-10-0001-01 and 35-10-0002-01 (released 22 July 2026; calendar 2025) and preliminary Table 35-10-0153-01 (released 9 July 2026; first quarter of 2026); Canadian Internet Use Survey 2022 results as reported on 21 October 2024.
Communications Security Establishment and the Canadian Centre for Cyber Security: Annual Reports 2025-2026 (June 2026; 1 April 2025 to 31 March 2026), 2024-2025 (June 2025) and 2023-2024 (June 2024); National Cyber Threat Assessment 2025-2026 (30 October 2024); Ransomware Threat Outlook 2025 to 2027 (web edition dated 28 January 2026, information as of 4 September 2025); statement on frontier AI (24 June 2026); Get Cyber Safe Awareness Tracking Survey 2026 (Phoenix SPI for CSE; 2,330 online Canadians aged 18 and older, 9 to 29 January 2026; margin of error 2.1 percentage points, 19 times out of 20).
Canadian Anti-Fraud Centre and RCMP: Top 10 frauds in 2025 (February 2026); Fraud Prevention Month 2025 (2024 data); RCMP Fraud Prevention Month 2024 release (2023 data); CAFC 2022 Annual Report (2021 and 2022 data); CAFC 2021 Annual Report (2021 data as first published); RCMP reporting-system release (6 November 2025).
Office of the Privacy Commissioner of Canada: Annual Reports to Parliament 2025-2026 (tabled 4 June 2026) and 2024-2025 (5 June 2025), fiscal years ending 31 March.
Provincial regulators: Quebec CAI Rapport annuel d'activités et de gestion 2024-2025 (October 2025; fiscal year to 31 March 2025); IPC Ontario 2025 Annual Report (5 August 2026; calendar 2025); OIPC Alberta Annual Report 2024-25 (December 2025; fiscal year to 31 March 2025); OIPC British Columbia Annual Report and Service Plan 2025/26 (25 June 2026; fiscal year to 31 March 2026).
IBM: Cost of a Data Breach Report 2026 Canada release (29 July 2026; breaches at 602 organizations globally between March 2025 and February 2026, researched by Ponemon Institute), plus the Canada releases for the 2023, 2024 and 2025 editions for the trend.
CIRA: 2025 Cybersecurity Survey (conducted by The Strategic Counsel; 505 cybersecurity decision-makers at organizations with at least 50 employees; online, July to August 2025; published October 2025).
Limitations a reader should keep in mind:
Survey years differ. Statistics Canada's business figures describe 2023 and its individual figures describe 2022, CIRA's describe the 12 months before August 2025, and the Get Cyber Safe survey was fielded in January 2026. Federal and provincial regulators report fiscal years ending 31 March (CSE, the OPC, Quebec, Alberta and British Columbia), while police data, CAFC data and the Ontario IPC report calendar years.
Counts are reports, not attacks, and they overlap. One ransomware attack can appear as a Cyber Centre incident, a PIPEDA breach report, a provincial notice, a police report and a data point in IBM's study. Do not add the series together.
Figures get revised. Statistics Canada revises cybercrime data back one year with each annual release and warns that preliminary quarterly figures are not comparable period to period. Statistics Canada figures are from the 22 July 2026 tables (2024 revised once, 2025 not yet revised); CAFC figures are as given in the release cited for each year, and the CAFC restates earlier years.
Police data undercount. In a note on measuring child sexual abuse and exploitation material, Statistics Canada says the Supreme Court's 2024 decision in R. v. Bykovets, which requires a warrant or production order before police obtain subscriber information behind an IP address, may have impacted cybercrime investigations where an IP address is often the only known identifier, and that police data may therefore underestimate the prevalence of that offence. More broadly, police-reported data only reflect incidents that come to the attention of police.
Currency. All dollar figures are Canadian dollars; IBM figures keep IBM's CA$ notation. No figure has been converted between currencies.
Calculations. Percentages and averages marked as a Stingrai calculation are arithmetic on the source figures shown beside them.
Dropped figures. Figures that a government report attributes to an unnamed outside estimate, such as an average Canadian ransom payment the National Cyber Threat Assessment cites from one estimate, were left out. Stats that could not be reached on at least one verification pass against a named primary source were dropped rather than estimated.

Figure 1: Four ways to count cyber attacks in Canada. Sources: Statistics Canada, Canadian Survey of Cyber Security and Cybercrime (21 October 2024) and Table 35-10-0002-01 (22 July 2026); Canadian Anti-Fraud Centre and RCMP annual figures for 2021 to 2025, as published in each cited release; IBM Cost of a Data Breach Report, Canada releases, 2023 to 2026 editions.
How many cyber attacks happen in Canada?
Canada has no single national count of cyber attacks. Three official series measure different slices: the incidents the Canadian Centre for Cyber Security responds to, the cybercrimes reported to or detected by police, and the incidents businesses tell Statistics Canada actually impacted them.
Incidents handled by the Canadian Centre for Cyber Security
The Cyber Centre, part of the Communications Security Establishment, is Canada's technical and operational authority on cyber security. Its incident count covers federal institutions and Canadian organizations, chiefly critical infrastructure, that it detects or that report to it, and CSE says its definition of a cyber incident covers a wide range of attempted threat activity, whether successful or not (CSE Annual Report 2023-2024). It is a count of incidents handled, not of successful breaches.
Fiscal year (April to March) | Incidents responded to | Government of Canada | Canadian organizations | Source |
|---|---|---|---|---|
2023-24 | 2,192 | 1,017 | 1,175 (critical infrastructure) | CSE Annual Report 2023-2024 |
2024-25 | 2,561 | 1,155 | 1,406 (critical infrastructure) | CSE Annual Report 2024-2025 |
2025-26 | 3,216 | 1,528 | 1,688 (Canadian entities) | CSE Annual Report 2025-2026 |
The 2025-26 count is 26 percent higher than 2024-25 and 47 percent higher than 2023-24 (Stingrai calculation). CSE attributed the 2024-25 rise "largely" to an increase in cases targeting critical infrastructure (CSE Annual Report 2024-2025). In 2,282 of the 3,216 incidents in 2025-26, or 71 percent, the Cyber Centre identified the incident, notified the organization and supported the response; in the other 934, the organization reported the incident to the Cyber Centre.
CSE's annual reports also show how much early warning the Cyber Centre sends:
Alerts and advisories (2025-26): 25 alerts and 995 advisories.
National Cyber Threat Notification System (2025-26): more than 97,000 security alerts sent to 1,363 subscribed organizations, with nearly 450 organizations notified each week.
Pre-ransomware notifications: 67 sent to 67 Canadian organizations in 2025-26, compared with 336 sent to 309 organizations in 2024-25. CSE says the scope of these notifications fluctuates with its intelligence partnerships, so the drop does not by itself show fewer ransomware attempts.
Ransomware averted (2024-25 estimate): CSE estimated its pre-ransomware notifications may have averted 74 to 148 ransomware incidents, saving $6 million to $18 million.
Ransomware disruption (2025-26): CSE took concurrent action against 10 of the most significant ransomware groups causing harm to Canada and its allies.
Cybercrime reported to police
Statistics Canada's Uniform Crime Reporting Survey counts criminal incidents in which a computer or the internet was the target of the crime or the instrument used to commit it. Police recorded 90,643 cybercrime incidents in 2025, a rate of 218.6 per 100,000 people (Table 35-10-0002-01, released 22 July 2026).
Year | Police-reported cybercrime incidents | Rate per 100,000 population |
|---|---|---|
2020 | 65,141 | 171.9 |
2021 | 71,727 | 188.1 |
2022 | 80,246 | 206.6 |
2023 | 98,252 | 246.4 |
2024 | 96,143 | 233.9 |
2025 | 90,643 | 218.6 |
The 2025 count is 5.7 percent below the revised 2024 count of 96,143 and 39 percent above 2020 (Stingrai calculation). Statistics Canada cautions that the change between the two latest years should be read with care because counts, notably Toronto's, rise when revised a year later. The series starts in 2020 here because Statistics Canada flags earlier years as an undercount. Preliminary data for the first quarter of 2026 show 20,922 incidents (Table 35-10-0153-01, released 9 July 2026); Statistics Canada does not compute changes between preliminary quarters because the number of reporting police services varies.
Most police-reported cybercrime is financially motivated:
Cyber-related violation (2025) | Incidents | Share of total |
|---|---|---|
Fraud | 44,542 | 49% |
Extortion | 5,444 | 6% |
Identity fraud | 5,209 | 6% |
Identity theft | 1,060 | 1% |
All other cyber-related violations | 34,388 | 38% |
Total | 90,643 | 100% |
Source: Statistics Canada Table 35-10-0001-01, released 22 July 2026; shares are Stingrai calculations. The remaining category is mostly online harassment, threats and child sexual exploitation offences.
Police-reported cybercrime by province and territory
Province or territory | Incidents (2025) | Rate per 100,000 (2025) |
|---|---|---|
British Columbia | 21,656 | 380.1 |
New Brunswick | 2,880 | 364.2 |
Northwest Territories | 126 | 276.5 |
Nova Scotia | 2,790 | 255.2 |
Alberta | 12,564 | 249.7 |
Newfoundland and Labrador | 1,223 | 222.4 |
Prince Edward Island | 394 | 215.7 |
Yukon | 97 | 204.2 |
Saskatchewan | 2,552 | 203.7 |
Ontario | 31,893 | 196.4 |
Manitoba | 2,876 | 191.0 |
Quebec | 11,547 | 128.4 |
Nunavut | 45 | 107.6 |
Canada | 90,643 | 218.6 |
Source: Statistics Canada Table 35-10-0002-01. British Columbia and New Brunswick reported the highest rates in 2025, and Quebec the lowest among the provinces. Rates partly reflect how easily victims can report to their local police: Statistics Canada attributes a 2023 jump in London, Ontario largely to the start of online fraud reporting. New Brunswick's 2025 coverage is 90.9 percent because Saint John Police Force data are excluded, and Calgary's figures are suspected cybercrimes only.
How many Canadian businesses are hit
Statistics Canada runs the Canadian Survey of Cyber Security and Cybercrime, a mandatory national survey of businesses, on behalf of Public Safety Canada. In 2023, 16 percent of businesses with 10 or more employees were impacted by cyber security incidents, down from 18 percent in 2021 and 21 percent in 2019 (The Daily, 21 October 2024).
Business size | 2019 | 2021 | 2023 |
|---|---|---|---|
Small (10 to 49 employees) | 18% | 16% | 14% |
Medium (50 to 249 employees) | 29% | 25% | 23% |
Large (250 or more employees) | 44% | 37% | 30% |
All businesses | 21% | 18% | 16% |
Source: Statistics Canada, Table 22-10-0076-01 and The Daily, 21 October 2024. The survey counts only incidents that businesses considered impactful, so Statistics Canada cautions that it may not reflect the total number of cyber attacks in Canada. The 2025 cycle was collected from 14 January to 31 March 2026 (survey page); results had not been published as of 1 October 2026.
How cyber attacks reach Canadian businesses

Figure 2: Methods used in cyber security incidents that impacted Canadian businesses, 2021 and 2023, as a share of impacted businesses. The password cracking category was reworded in 2023. Source: Statistics Canada, Canadian Survey of Cyber Security and Cybercrime, The Daily, 21 October 2024, Chart 2.
Method used in the incident | 2021 | 2023 | Change |
|---|---|---|---|
Scams and fraud | 44% | 50% | +6 points |
Identity theft | 20% | 31% | +11 points |
Exploiting software, hardware or network vulnerabilities | 19% | 25% | +6 points |
Password cracking | 23% | 22% | -1 point |
Malicious software (excluding ransomware) | 21% | 18% | -3 points |
Ransomware | 11% | 13% | +2 points |
Source: Statistics Canada, share of businesses impacted by cyber security incidents that experienced each method. Statistics Canada notes that the password cracking category was reworded in 2023 from "Hacking or password cracking" and that the change may have had a small impact on the trend. Scams and fraud remained the most common method, and identity theft grew fastest. The rise in exploited vulnerabilities, from 19 to 25 percent of impacted businesses, is the change most directly addressed by testing.
Investigations summarized in Canadian privacy regulators' latest annual reports keep naming the same control gaps:
Remote access without multi-factor authentication. The Toronto Zoo ransomware attack in early 2024, which exposed personal information of about 1.2 million people, began with a compromised VPN account that was not protected by multi-factor authentication (IPC Ontario). The Limestone District School Board attack, affecting more than 32,000 students, staff, families and donors, found no multi-factor authentication on a legacy firewall appliance.
Credentials shared or reused. The OPC found that a threat actor at Ticketmaster Canada obtained the credentials of a service account, and that a credential-stuffing attack on 23andMe affected nearly 320,000 Canadians (OPC Annual Report 2025-2026).
Real data in test environments. A ransomware attack on a Toronto District School Board test environment exposed personal information of about 280,000 students and staff (IPC Ontario).
Shared providers. A ransomware attack on a shared IT provider compromised personal health information held by five hospitals and one clinic, and the IPC reminded custodians they remain responsible for safeguarding it even when relying on external vendors.
Ransomware in Canada
The National Cyber Threat Assessment 2025-2026 calls ransomware the top cybercrime threat facing Canada's critical infrastructure. The Cyber Centre's Ransomware Threat Outlook 2025 to 2027 reports a 26 percent average year-over-year increase in Canadian ransomware incidents known to it from 2021 to 2024, estimated to continue through 2025, and an increase in 2024 over 2023. The top three ransomware threats to Canada in 2024 were Akira, Play and Medusa. The Cyber Centre adds that, due to underreporting, the true number of incidents and payments is almost certainly higher than it observes.
Ransomware growth by sector
Sector | Increase in Canadian ransomware incidents observed by the Cyber Centre, 2022 to 2023 |
|---|---|
Information technology | 159% |
Finance | 157% |
Construction | 133% |
Transportation | 122% |
Professional services | 112% |
Retail | 90% |
Healthcare | 75% |
Energy | 67% |
Source: Canadian Centre for Cyber Security, National Cyber Threat Assessment 2025-2026, Figure 12. The Cyber Centre judges that ransomware actors choose victims by opportunity rather than by sector, so these increases say more about where attackers found openings than about deliberate targeting.
Do Canadian ransomware victims pay?
The two Canadian sources that ask this question reach opposite answers, because they survey different organizations.
Measure | Statistics Canada, CSCSC 2023 | CIRA Cybersecurity Survey 2025 |
|---|---|---|
Period | Calendar 2023 | 12 months before July to August 2025 |
Who answered | Mandatory survey, enterprises with 10 or more employees; 12,462 sampled, 71% response | 505 cybersecurity decision-makers at organizations with 50 or more employees (private sector up to 999), online |
Ransomware incidence | 13% of businesses impacted by a cyber incident | 24% of organizations hit by a successful ransomware attack |
Paid the ransom | 88% of victims did not pay | 74% of victims paid |
Amount paid | 84% of payers paid less than $10,000; 4% paid more than $500,000 | Payers typically paid at least $25,000 |
Sources: Statistics Canada; CIRA 2025 Cybersecurity Survey. Statistics Canada's figure works out to roughly 2 percent of all businesses in scope experiencing a ransomware attack that impacted them in 2023 (Stingrai calculation: 13 percent of the 16 percent impacted). CIRA's sample excludes the smallest firms, where Statistics Canada finds most businesses sit, and it reports larger organizations' experience.
CIRA's series shows how the larger-organization picture has moved:
CIRA survey year | Organizations hit by a successful ransomware attack | Victims that paid | Respondents (all, victims) |
|---|---|---|---|
2021 | 17% | 69% | 510, 87 |
2022 | 22% | 73% | 500, 111 |
2023 | 23% | 70% | 500, 113 |
2024 | 28% | 79% | 500, 141 |
2025 | 24% | 74% | 505, 122 |
Source: CIRA, 2025 Cybersecurity Survey full report. In 2025, 27 percent of private-sector respondents reported a successful ransomware attack, against 14 percent in the public sector and 12 percent in municipalities, universities, schools and hospitals (a small sample of 41), and 74 percent of victims said data was exfiltrated. For payout trends beyond Canada, see our ransomware payout statistics.
Ransomware in breach notices
Ransomware also shows up in privacy regulators' files. Quebec's Commission d'accès à l'information cited ransomware in 106 of the confidentiality incident notices it received in 2024-25, behind cyberattacks (160) and human error (110). The Ontario IPC opened 3 self-reported health breach files caused by ransomware and 47 caused by cyberattacks in 2025.
Fraud and impersonation
The Canadian Anti-Fraud Centre, jointly managed by the RCMP, the Competition Bureau and the Ontario Provincial Police, collects fraud reports from individuals and businesses. Its annual figures are the main public record of money Canadians report losing to fraud, and the trend appears in the third panel of Figure 1.
Year | Fraud losses reported to the CAFC | Fraud reports | Source |
|---|---|---|---|
2021 | About $383 million | Not stated | CAFC 2022 Annual Report |
2022 | $530.4 million | Not stated | CAFC 2022 Annual Report |
2023 | $567 million | 116,403 | RCMP, February 2024 |
2024 | More than $638 million | 108,878 | CAFC, Fraud Prevention Month 2025 |
2025 | More than $704 million | More than 112,000 | CAFC, Top 10 frauds in 2025 |
Sources: CAFC 2022 Annual Report; RCMP; CAFC, Fraud Prevention Month 2025; CAFC, Top 10 frauds in 2025. Each figure is from the release named; the CAFC restates earlier years (2021 was first published as $379 million, and the RCMP later put 2024 at more than $648 million). Losses rose about 9 to 10 percent from 2024 to 2025 and about 84 percent from 2021 to 2025 (Stingrai calculation), while the number of reports did not grow: 116,403 in 2023, 108,878 in 2024 and more than 112,000 in 2025.
The frauds that cost Canadians the most in 2025
Fraud type | Reports | Victims | Reported loss | Loss per victim (approx.) |
|---|---|---|---|---|
Investments | 4,409 | 3,867 | $351 million | $90,800 |
Spear phishing | 813 | 571 | $67.9 million | $118,900 |
Relationship | 1,093 | 933 | $63.3 million | $67,800 |
Job | 2,148 | 1,726 | $50.6 million | $29,300 |
Fraud investigator | 2,167 | 1,137 | $28.3 million | $24,900 |
Recovery pitch | 933 | 569 | $25.9 million | $45,500 |
Extortion | 2,767 | 835 | $23 million | $27,500 |
Service | 3,393 | 2,444 | $19.5 million | $8,000 |
Merchandise | 2,596 | 2,222 | $11.7 million | $5,300 |
Prize | 403 | 151 | $5.7 million | $37,700 |
Source: CAFC, Top 10 frauds in 2025 (February 2026). Loss per victim is a Stingrai calculation from the CAFC's rounded losses. By number of reports, identity fraud led with 8,403, followed by investments (4,409), service fraud (3,393), personal information fraud (3,016) and phishing (2,869). The CAFC notes that phishing and personal information frauds do not involve financial losses and that most identity fraud victims are not responsible for the losses.
Spear phishing is the business-facing fraud
The CAFC defines spear phishing as fraudsters "pretending to be from legitimate sources to convince businesses or individuals to send them money", using existing relationships between sender and recipient (CAFC). Its variants include business executive spoofs, payroll spoofs, supplier and contractor swindles, and spoofed instructions from a financial institution's client. In 2025 it produced the second-largest loss of any fraud type, $67.9 million, from only 571 victims. Our business email compromise statistics cover the same attack in the United States and globally.
Most fraud and cybercrime is never reported
The RCMP estimates that only 5 to 10 percent of fraud and cybercrime incidents are reported in Canada, "whether due to embarrassment, fear of reputational damage, or a lack of awareness" (RCMP, 6 November 2025). That release launched a national Report Cybercrime and Fraud system run by the RCMP's National Cybercrime Coordination Centre and the CAFC, which should make future Canadian counts more complete. Businesses underreport too: only 13 percent of businesses impacted in 2023 told police, mostly because incidents were resolved internally (55 percent), seemed too minor (35 percent) or were resolved by IT consultants (31 percent).
Data breaches reported to privacy regulators
Federal: the Office of the Privacy Commissioner of Canada
Businesses subject to PIPEDA must report breaches of security safeguards that pose a real risk of significant harm and keep records of all breaches, and federal institutions subject to the Privacy Act also report breaches to the OPC (OPC breach reporting guidance). The OPC's 2025-2026 Annual Report, tabled 4 June 2026, covers the fiscal year to 31 March 2026.
Measure | 2024-25 | 2025-26 |
|---|---|---|
Breach reports from businesses (PIPEDA) | 686 | 696 |
Breach reports from federal institutions (Privacy Act) | 615 | 451 |
Total breach reports | 1,301 | 1,147 |
Canadian accounts affected, PIPEDA reports | 20,087,391 | 20,328,495 |
Canadians affected, Privacy Act reports | 309,865 | 48,159 |
All reports combined | 20,397,256 (Stingrai calculation) | 20,376,654 |
Sources: OPC Annual Report 2025-2026; OPC Annual Report 2024-2025, Table 8 and the Privacy Act breach section. Like for like, accounts affected in PIPEDA reports rose 1.2 percent and the combined total was flat, down 0.1 percent (Stingrai calculation). PIPEDA reports count Canadian accounts, so one person can be counted more than once.

Figure 3: Breach reports filed by businesses under PIPEDA, by sector, fiscal 2025-26 (696 reports). Source: Office of the Privacy Commissioner of Canada, 2025-2026 Annual Report to Parliament, Table 5.
What drove the business breach reports in 2025-26:
Unauthorized access: 542 of 696 PIPEDA reports (78 percent), and those reports covered 20,235,305 of the 20,328,495 affected accounts.
Causes of unauthorized access: cybersecurity incidents 68 percent, social engineering 13 percent, employees misusing access privileges 8 percent.
Other breach types: unauthorized disclosure 112, theft 21, loss 13, other 8.
Harm: 58 percent of PIPEDA breaches and 94 percent of Privacy Act breaches were assessed as likely to cause a real risk of significant harm.
Sectors: the financial sector filed 172 reports, telecommunications 91, insurance 62, services 53 and sales and retail 52.
In the public sector, mishandling of information caused 368 Privacy Act breaches, followed by cyber incidents (39), employee snooping (22) and security vulnerabilities (19). Employment and Social Development Canada filed 69 percent of public-sector reports, 86 percent of them lost passports, and the Canada Revenue Agency 11 percent.
Provincial privacy regulators
Regulator | Period | Breach notifications received | Prior period | What the regulator reports |
|---|---|---|---|---|
Quebec, Commission d'accès à l'information | Fiscal 2024-25 | 514 confidentiality incident notices | Up 16% in a year, 559% over three years | 80% from the private sector; top causes cyberattack (160), human error (110) and ransomware (106) |
Ontario, IPC (health information custodians) | Calendar 2025 | 12,075 breaches reported in annual statistics | 11,970 in 2024 | Misdirected faxes 5,438 (45%) |
Ontario, IPC (health breaches self-reported to the IPC) | Calendar 2025 | 785 files opened | 709 in 2024 | Snooping 280; cyberattack 47; ransomware 3 |
Ontario, IPC (provincial institutions, FIPPA) | 1 July to 31 December 2025 | 75 breaches | First period of mandatory reporting | New duty took effect 1 July 2025 |
Alberta, OIPC (private sector, PIPA) | Fiscal 2024-25 | 388 self-reported breaches | 380 in 2023-24; 313 in 2022-23 | Cyber attacks remain the main cause of private-sector breaches |
Alberta, OIPC (health, HIA) | Fiscal 2024-25 | 492 self-reported breaches | 448 in 2023-24 | Mix of employee snooping and cyber attacks |
British Columbia, OIPC | Fiscal 2025-26 | 531 (297 public bodies, 234 private organizations) | 418 in 2024-25 (208 and 210) | Up 27% in a year (Stingrai calculation) |
Sources: CAI Rapport annuel 2024-2025 (in French); IPC Ontario 2025 statistics; OIPC Alberta Annual Report 2024-25; OIPC British Columbia Annual Report and Service Plan 2025/26. Reporting obligations and thresholds differ by province and sector, so these counts are not comparable with each other. In Quebec, organizations must notify the CAI of any confidentiality incident that presents a risk of serious injury to the people concerned; our Quebec Law 25 guide explains what the incident rules mean for security testing.
Of Quebec's 514 notices, the most came from health care and social assistance (94), finance and insurance (89) and professional, scientific and technical services (61), together 47 percent (Stingrai calculation). Phishing was cited in 48 notices and social engineering in 15.
Breaches documented in regulators' latest annual reports
Incident | What the regulator reported | People affected | Source |
|---|---|---|---|
PowerSchool education platform | Cyberattack exposing data on students, parents and educators in several provinces; commitments made in July 2025 | Millions of Canadians | OPC Annual Report 2025-2026 |
Nova Scotia Power | Breach notified to the OPC in May 2025; compliance letter signed March 2026 | About 375,000 current and 540,000 former customers | OPC Annual Report 2025-2026 |
Toronto Zoo | Ransomware attack in early 2024 starting from a VPN account without multi-factor authentication | About 1.2 million people | IPC Ontario 2025 Annual Report |
23andMe | Credential-stuffing attack | Nearly 320,000 Canadians | OPC Annual Report 2025-2026 |
Toronto District School Board | Ransomware attack on a test environment holding real personal information | About 280,000 students and staff | IPC Ontario 2025 Annual Report |
Limestone District School Board | Ransomware attack; no multi-factor authentication on a legacy firewall appliance | More than 32,000 people | IPC Ontario 2025 Annual Report |
Brookfield Global Relocation Services and Sirva | Breach of relocation records of public service employees | About 27,000 people in Canada | OPC Annual Report 2025-2026 |
What a cyber attack costs in Canada
IBM Cost of a Data Breach, Canada
IBM report edition | Average cost of a data breach in Canada | Source |
|---|---|---|
2022 | CA$7.05 million | IBM Canada release, 24 July 2023 |
2023 | CA$6.94 million | IBM Canada release, 24 July 2023 |
2024 | CA$6.32 million | IBM Canada release, 30 July 2024 |
2025 | CA$6.98 million | IBM Canada release, 30 July 2025 |
2026 | CA$7.11 million (record) | IBM Canada release, 29 July 2026 |
Sources: IBM 2026; IBM 2025; IBM 2024; IBM 2023. Each edition is labeled by report year; the 2026 edition covers breaches between March 2025 and February 2026.
What the 2026 Canadian findings add:
2026 finding (Canada) | Figure |
|---|---|
Costliest sector | Energy, CA$9.21 million per breach |
Next costliest sectors | Technology CA$9.02 million; industrial CA$8.89 million |
Largest factor raising breach cost | Supply-chain compromise, adding about CA$367,899 |
Next largest factors | Security skills shortages (+$314,500); challenges prioritizing threats (+$311,300) |
Average breach lifecycle | 205 days, up 6% |
Average records compromised | 28,500, up 8% |
Extensive security AI vs none | CA$5.5 million vs CA$8.91 million (CA$3.41 million less) |
Time to detect and contain, extensive AI vs none | 124 and 57 days vs 154 and 71 days |
Organizations reporting an AI-generated attack | 28% |
Source: IBM Cost of a Data Breach Report 2026, Canada release, 29 July 2026. In the 2025 edition, phishing was the most common initial attack vector in Canada, at CA$7.91 million per breach, and the financial sector had the highest costs at CA$9.97 million. IBM's averages come from a study of organizations that suffered a breach, not a census of Canadian breaches. For what preventive testing costs against these figures, see our guide to penetration testing costs in Canada.
What Canadian businesses spend
Statistics Canada measures the whole business population rather than breached organizations. In 2023, Canadian businesses spent:
$1.2 billion on recovery from cyber security incidents, double the roughly $600 million of 2021; large businesses spent about $500 million, and medium and small businesses about $300 million each.
$11.0 billion on prevention and detection, up from $9.7 billion in 2021, including $3.8 billion in employee salaries, $2.9 billion on security software and $1.9 billion on consultants and contractors.
At the same time, the share of businesses spending anything on prevention or detection fell from 61 to 56 percent, and the share with cyber security employees fell from 61 to 50 percent; 47 percent of businesses without such employees relied on consultants or contractors instead. Cyber risk insurance rose to 22 percent of businesses from 16 percent, only 26 percent had written cyber security policies, and 22 percent gave non-IT staff formal cyber security training.
How Canadians experience cyber attacks
Measure | Figure | Source |
|---|---|---|
Canadians aged 15 and older who experienced a cyber security incident (2022) | 70%, up from 58% in 2020 and 52% in 2018 | Statistics Canada, Canadian Internet Use Survey |
Online Canadians who have experienced a cyber incident other than a scam with losses (surveyed January 2026) | 59% | Get Cyber Safe 2026 |
Most common incidents (January 2026) | Email scams 31%; text scams 26%; malware 26%; phishing 26% | Get Cyber Safe 2026 |
Victims of a phishing scam where they lost money or data | 8% | Get Cyber Safe 2026 |
Victims of a ransomware attack | 4% | Get Cyber Safe 2026 |
Worried about AI-related cybercrime | 73%, up from 65% in 2024 | Get Cyber Safe 2026 |
Worried about falling victim to cybercrime in general | 56%, up from 51% in 2024 | Get Cyber Safe 2026 |
Reuse the same password across multiple accounts | 26% | Get Cyber Safe 2026 |
Sources: Statistics Canada, The Daily, 21 October 2024; Get Cyber Safe Awareness Tracking Survey 2026. Get Cyber Safe figures describe online Canadians aged 18 and older. The two surveys use different questions and samples and should not be compared directly. The 2022 Canadian Internet Use Survey is the latest edition with incident data.
State actors, critical infrastructure and AI
The National Cyber Threat Assessment 2025-2026 names the People's Republic of China's cyber program as "the most sophisticated and active state cyber threat to Canada today" and reports that at least 20 networks associated with Government of Canada agencies and departments were compromised by PRC cyber threat actors over the past four years. It also assesses Russia, Iran and India as sources of state cyber activity against Canadian targets, and it judges that fraud and scams are almost certainly the most common form of cybercrime affecting Canadians. Critical infrastructure incidents it lists include the 2023 MOVEit breach at the Government of Nova Scotia, which affected an estimated 100,000 current and past provincial employees, and a ransomware incident that hit five hospitals in Southern Ontario in October 2023. Our analysis of Bill C-8 and the Critical Cyber Systems Protection Act covers the federal rules aimed at these operators.
AI is the newest accelerant. In its 24 June 2026 statement, the Cyber Centre said frontier models can help attackers find and exploit vulnerabilities much faster than before, shortening the time defenders have to respond in some cases from days or weeks to hours, and that attackers already use AI for more convincing phishing, voice scams and deepfake impersonation and to chain weaknesses together. IBM's 2026 study found 28 percent of Canadian organizations reported an AI-generated attack, CIRA's 2025 survey found 70 percent of organizations worried about generative AI threats, and 73 percent of online Canadians told the Get Cyber Safe survey they worry about AI-related cybercrime.
What this means for defenders
Test the doors attackers now use first. Exploited software, hardware and network vulnerabilities rose from 19 to 25 percent of impacted Canadian businesses between 2021 and 2023, and the Cyber Centre warns frontier AI can shrink the response window to hours in some cases. Test internet-facing systems and the applications behind them at least annually and after significant change, through external and internal network penetration testing and web application penetration testing.
Treat credentials and remote access as the perimeter. Breaches examined in Canadian regulators' latest annual reports turned on a VPN account without multi-factor authentication, a legacy firewall without it, a compromised service account and credential stuffing. An Active Directory security assessment and identity-focused testing show whether one stolen password still opens the network.
Rehearse impersonation, not only phishing clicks. Spear phishing cost Canadian victims $67.9 million in 2025, about $119,000 each, and social engineering caused 13 percent of the unauthorized-access breaches businesses reported under PIPEDA. Phishing and vishing campaigns should target payment approvals, payroll changes and help-desk resets, the processes these frauds exploit.
Assume ransomware will land, and test containment. The Cyber Centre's June 2026 guidance asks organizations to segment key systems and test incident response plans, and IBM found supply-chain compromise is now the largest single factor raising Canadian breach costs. Red team engagements and segmentation testing show how far an intruder gets, including through shared service providers.
Keep evidence regulators can read. Regulators review safeguards after a breach: the OPC's 2025-26 investigations found inadequate safeguards at 23andMe and Sirva, and Nova Scotia Power signed a compliance letter in March 2026. Federally regulated financial institutions should also read our OSFI B-13 penetration testing guide.
How Stingrai tests Canadian organizations against these attacks
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
For Canadian organizations, that means a Toronto-headquartered firm, CREST-accredited at firm level, whose two named penetration testers work each human-led engagement against the entry points the figures above keep pointing to: internet-facing services, VPN and identity configurations, Active Directory attack paths, payment and payroll approval workflows, and the help desk. The team holds 18 published CVEs. Findings are posted to the PTaaS portal as they are confirmed, each with a working proof of concept and remediation guidance, and every engagement includes retesting, and human-led and hybrid engagements include an attestation letter. Engagements run as one-time annual tests or as continuous programs, and the reports give you pentest evidence for PIPEDA safeguards reviews, Quebec Law 25 programs and OSFI B-13. For one web application and its APIs, published prices are US$3,000 per assessment or US$650 per month for the Autonomous Pentest by Snipe, Stingrai's AI agent for web applications and APIs, which carries the No High or Critical Finding = Don't Pay guarantee, and US$6,800 per assessment or US$1,275 per month for the Hybrid Pentest, in which Snipe and penetration testers test together; the monthly prices are for 12-month continuous plans (pricing). Network, Active Directory, cloud, red team and social engineering scopes are quoted through the quote form. Buyers comparing providers can start with our ranking of penetration testing companies in Canada.
Frequently Asked Questions
How many cyber attacks happen in Canada each year?
There is no single national count. The Canadian Centre for Cyber Security responded to 3,216 cyber security incidents affecting federal institutions and Canadian organizations in fiscal 2025-26, up from 2,561 a year earlier (CSE Annual Report 2025-2026). Police recorded 90,643 cybercrime incidents in 2025 (Statistics Canada), and the RCMP estimates only 5 to 10 percent of fraud and cybercrime incidents are reported, so both counts are floors.
What is the average cost of a data breach in Canada in 2026?
The average cost of a data breach in Canada is CA$7.11 million in the IBM Cost of a Data Breach Report 2026, released 29 July 2026, the highest level since the study began and up from CA$6.98 million in the 2025 edition. Energy organizations had the costliest breaches at CA$9.21 million, followed by technology at CA$9.02 million and industrial organizations at CA$8.89 million. The study, conducted by Ponemon Institute, covers breaches between March 2025 and February 2026.
How much money did Canadians lose to fraud in 2025?
Canadians reported more than $704 million in fraud losses to the Canadian Anti-Fraud Centre in 2025, across more than 112,000 reports, up from more than $638 million in 2024 (CAFC). Investment fraud caused the largest losses at $351 million, followed by spear phishing at $67.9 million and relationship fraud at $63.3 million. Because the RCMP estimates only 5 to 10 percent of fraud and cybercrime is reported, actual losses are higher.
How common is ransomware in Canada?
Ransomware incidents known to the Canadian Centre for Cyber Security grew by an average of 26 percent a year from 2021 to 2024, and the Cyber Centre calls ransomware the top cybercrime threat to Canada's critical infrastructure. Statistics Canada found 13 percent of businesses impacted by a cyber incident in 2023 were hit by ransomware, and 88 percent of those victims did not pay. CIRA's 2025 survey of organizations with 50 or more employees found 24 percent suffered a successful ransomware attack in the previous 12 months, and 74 percent of those victims paid.
How many data breaches are reported to the Privacy Commissioner of Canada?
The Office of the Privacy Commissioner of Canada received 1,147 breach reports in fiscal 2025-26: 696 from businesses under PIPEDA, affecting 20,328,495 Canadian accounts, and 451 from federal institutions under the Privacy Act, affecting 48,159 Canadians (OPC Annual Report 2025-2026). Unauthorized access accounted for 78 percent of PIPEDA reports, and 68 percent of those were cybersecurity incidents. The financial sector filed the most PIPEDA reports, 172 of 696.
Which sectors in Canada are hit hardest by cyber attacks?
It depends on the measure. The financial sector filed the most PIPEDA breach reports in 2025-26 (172 of 696), followed by telecommunications (91) and insurance (62). IBM's 2026 report found the costliest breaches in energy, at CA$9.21 million on average. The Cyber Centre measured the fastest growth in ransomware incidents from 2022 to 2023 in information technology (159 percent) and finance (157 percent), and Quebec's regulator received the most incident notices from health care and social assistance (94).
What share of Canadian businesses experience cyber attacks?
Statistics Canada's latest Canadian Survey of Cyber Security and Cybercrime found 16 percent of businesses with 10 or more employees were impacted by cyber security incidents in 2023, down from 18 percent in 2021 and 21 percent in 2019. Large businesses were the most likely to be impacted, at 30 percent. Recovery spending still doubled to $1.2 billion, and the 2025 survey, collected from January to March 2026, has not yet been published.
Why do Canadian cyber attack statistics disagree?
They count different things. The Cyber Centre counts incidents it responds to, police count crimes reported to or detected by them, privacy regulators count breach notices that meet legal thresholds, Statistics Canada surveys businesses about incidents that impacted them, and IBM and CIRA survey samples of organizations. Reporting periods also differ between fiscal and calendar years, and the RCMP estimates only 5 to 10 percent of fraud and cybercrime incidents are reported at all.
Where can I get the latest Canadian cyber attack data?
Statistics Canada publishes police-reported cybercrime each July and runs its business cyber survey every two years; the Canadian Anti-Fraud Centre publishes the previous year's fraud losses in February or March; the Communications Security Establishment reports Cyber Centre incidents in its annual report each June; and the Office of the Privacy Commissioner reports breach notifications in its annual report, tabled in June in 2025 and 2026. IBM's Canadian breach cost figures arrive each July. The references below link every edition used in this post.
References
Communications Security Establishment Canada. Communications Security Establishment Canada Annual Report 2025-2026. June 2026. https://www.cse-cst.gc.ca/en/accountability/transparency/reports/communications-security-establishment-canada-annual-report-2025-2026. Cyber Centre incident counts, alerts, advisories, notifications and ransomware disruption for 1 April 2025 to 31 March 2026.
Communications Security Establishment Canada. Communications Security Establishment Canada Annual Report 2024-2025. June 2025. https://www.cse-cst.gc.ca/en/accountability/transparency/reports/communications-security-establishment-canada-annual-report-2024-2025. Cyber Centre incident counts for 2023-24 and 2024-25 and pre-ransomware notification outcomes.
Communications Security Establishment Canada. Communications Security Establishment Annual Report 2023-2024. June 2024. https://www.cse-cst.gc.ca/en/accountability/transparency/reports/communications-security-establishment-annual-report-2023-2024. Cyber Centre incident count for 2023-24 by federal institutions and critical infrastructure, and the definition of a cyber incident.
Canadian Centre for Cyber Security. National Cyber Threat Assessment 2025-2026. 30 October 2024. https://www.cyber.gc.ca/en/guidance/national-cyber-threat-assessment-2025-2026. Biennial assessment of state and criminal cyber threats to Canada, including ransomware growth by sector.
Canadian Centre for Cyber Security. Ransomware Threat Outlook 2025 to 2027. Web edition dated 28 January 2026, information as of 4 September 2025. https://www.cyber.gc.ca/en/guidance/ransomware-threat-outlook-2025-2027. Trend in Canadian ransomware incidents known to the Cyber Centre and the top ransomware groups affecting Canada.
Canadian Centre for Cyber Security. Statement on frontier artificial intelligence models and their impact on cyber security. 24 June 2026. https://www.canada.ca/en/communications-security/news/2026/06/statement-from-the-canadian-centre-for-cyber-security-on-frontier-ai-models-and-their-impact-on-cyber-security.html. How AI shortens exploitation timelines and the controls the Cyber Centre recommends.
Phoenix Strategic Perspectives for the Communications Security Establishment. Get Cyber Safe Awareness Tracking Survey: 2026 Final Report. Delivered 13 March 2026. https://epe.bac-lac.gc.ca/100/200/301/pwgsc-tpsgc/por-ef/communications_security_establishment/2026/052-25-e/report.html. Online survey of 2,330 Canadians aged 18 and older, 9 to 29 January 2026.
Statistics Canada. Impact of cybercrime on Canadian businesses, 2023 (The Daily). 21 October 2024. https://www150.statcan.gc.ca/n1/daily-quotidien/241021/dq241021a-eng.htm. Canadian Survey of Cyber Security and Cybercrime results for 2023, with Canadian Internet Use Survey context.
Statistics Canada. Table 35-10-0002-01, Police-reported cybercrime, number of incidents and rate per 100,000 population. 22 July 2026. https://www150.statcan.gc.ca/t1/tbl1/en/tv.action?pid=3510000201. Annual counts and rates for Canada, provinces, territories and metropolitan areas, 2014 to 2025.
Statistics Canada. Table 35-10-0001-01, Police-reported cybercrime, by cyber-related violation. 22 July 2026. https://www150.statcan.gc.ca/t1/tbl1/en/tv.action?pid=3510000101. Annual cybercrime counts by offence type.
Statistics Canada. Table 35-10-0153-01, Police-reported cybercrime, preliminary quarterly data. 9 July 2026. https://www150.statcan.gc.ca/t1/tbl1/en/tv.action?pid=3510015301. Preliminary quarterly counts through the first quarter of 2026.
Statistics Canada. Police-reported crime statistics in Canada, 2025 (The Daily). 22 July 2026. https://www150.statcan.gc.ca/n1/daily-quotidien/260722/dq260722a-eng.htm. Annual crime release, including the note on how the Bykovets decision may affect cybercrime counts.
Statistics Canada. Canadian Survey of Cyber Security and Cybercrime (survey 5244). Page updated 19 August 2026. https://www.statcan.gc.ca/en/survey/business/5244. Collection dates for the 2025 survey cycle.
Canadian Anti-Fraud Centre. Top 10 frauds in 2025. February 2026. https://antifraudcentre-centreantifraude.ca/features-vedette/2026/02/top-fraud-2025-fraudes-plus-courantes-eng.htm. Reports, victims and dollar losses by fraud type for 2025.
Canadian Anti-Fraud Centre. Fraud Prevention Month 2025. March 2025. https://antifraudcentre-centreantifraude.ca/features-vedette/2025/02/month-prevention-mois-eng.htm. Fraud reports and losses for 2024.
Royal Canadian Mounted Police. Fraud Prevention Month 2024: Fighting fraud in the digital era. February 2024. https://rcmp.ca/en/news/2024/02/fraud-prevention-month-2024-fighting-fraud-digital-era. Fraud losses and report counts for 2023.
Canadian Anti-Fraud Centre. CAFC 2022 Annual Report. Page updated 19 April 2024. https://antifraudcentre-centreantifraude.ca/annual-reports-2022-rapports-annuels-eng.htm. Reported fraud losses for 2021 and 2022.
Canadian Anti-Fraud Centre. CAFC 2021 Annual Report. Page updated 30 November 2022. https://antifraudcentre-centreantifraude.ca/annual-reports-2021-rapports-annuels-eng.htm. Reported fraud losses for 2020 and 2021 as first published.
Royal Canadian Mounted Police. RCMP launches new National Cybercrime and Fraud Reporting System. 6 November 2025. https://rcmp.ca/en/news/2025/11/rcmp-launches-new-national-cybercrime-and-fraud-reporting-system. National reporting system launch, the estimate that 5 to 10 percent of incidents are reported, and the restated 2024 fraud loss total of more than $648 million.
Canadian Anti-Fraud Centre. Spear phishing. Web page, accessed 1 October 2026. https://antifraudcentre-centreantifraude.ca/scams-fraudes/spear-phishing-harponnage-eng.htm. Definition and variants of spear phishing fraud.
Office of the Privacy Commissioner of Canada. Championing privacy in the age of AI: 2025-2026 Annual Report to Parliament. 4 June 2026. https://www.priv.gc.ca/en/opc-actions-and-decisions/ar_index/202526/ar_202526/. Breach reports under PIPEDA and the Privacy Act by sector, type and cause, with investigation summaries.
Office of the Privacy Commissioner of Canada. Prioritizing privacy in a data-driven world: 2024-2025 Annual Report to Parliament. 5 June 2025. https://www.priv.gc.ca/en/opc-actions-and-decisions/ar_index/202425/ar_202425/. Prior-year breach report counts.
Commission d'accès à l'information du Québec. Rapport annuel d'activités et de gestion 2024-2025. October 2025. https://www.cai.gouv.qc.ca/uploads/pdfs/CAI_RAAG-2024-2025.pdf. Confidentiality incident notices by cause and sector, in French.
Information and Privacy Commissioner of Ontario. Strong Foundations for a Changing World: 2025 Annual Report. 5 August 2026. https://www.ipc.on.ca/en/2025-annual-report/statistics. Health, provincial and child and family services breach statistics, with tribunal decisions on ransomware cases.
Office of the Information and Privacy Commissioner of Alberta. Annual Report 2024-25. December 2025. https://oipc.ab.ca/wp-content/uploads/2025/12/Annual_Report_2024-25-Online-version.pdf. Self-reported breach cases under PIPA, the Health Information Act and the FOIP Act.
Office of the Information and Privacy Commissioner for British Columbia. Annual Report and Service Plan 2025/26. 25 June 2026. https://www.oipc.bc.ca/documents/budget-annual-report-service-plans/3188. Privacy breach notifications under FIPPA and PIPA for 2024-25 and 2025-26.
IBM. IBM Report: Canada's Data Breach Costs Hit Record High as Attacks Target Critical Infrastructure. 29 July 2026. https://canada.newsroom.ibm.com/2026-07-29-IBM-Report-Canadas-Data-Breach-Costs-Hit-Record-High-as-Attacks-Target-Critical-Infrastructure. Canadian findings of the Cost of a Data Breach Report 2026, researched by Ponemon Institute.
IBM. Cost of a Data Breach Report, Canada releases for the 2023, 2024 and 2025 editions. 24 July 2023, 30 July 2024 and 30 July 2025. https://canada.newsroom.ibm.com/2025-07-30-IBM-Report-Canadians-Data-Security-Under-Increased-Threat,-While-Breach-Costs-Surge. Earlier Canadian averages used for the five-edition trend, with the 2024 and 2023 releases linked in the cost section.
CIRA (Canadian Internet Registration Authority). 2025 CIRA Cybersecurity Survey. October 2025. https://www.cira.ca/en/resources/documents/cybersecurity/2025-cybersecurity-survey/. Survey of 505 Canadian cybersecurity decision-makers on attacks, ransomware, payments and breaches, conducted by The Strategic Counsel.
Related reading
Top penetration testing companies in Canada (2026): twelve providers ranked on accreditation, named testers, retesting and published pricing.
Average cost of a penetration test in Canada (2026): Canadian price ranges by scope.
Quebec Law 25 and penetration testing: what the confidentiality incident rules mean for testing.
OSFI B-13 penetration testing: testing expectations for federally regulated financial institutions.
Data breach statistics 2026: the global picture behind the Canadian numbers.
Business email compromise statistics 2026: losses from the impersonation attacks the CAFC calls spear phishing.



