CSIDB logo
Incident

Sun Media Corp

Incident posture

Attack window
Sep 1996
Location
Canada
Status
Historical
CIA posture
Available to members
Updated
2026-08-29 03:41

Linked entities

Victim
Sun Media Corp
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Sep 2017
Disclosed
Sep 2017
Resolved
Pending

Summary

Canoe.ca disclosed that a breach exposed personal information of roughly one million users, including names, email addresses, mailing addresses and telephone numbers, collected through contests, forums, comment sections and personal pages. The investigation found no financial data or social insurance numbers among the compromised records. After discovering the incident, the organization launched an investigation, enlisted security experts, and informed the RCMP, the Office of the Privacy Commissioner and relevant provincial privacy authorities. It also provided a contact number for affected users seeking assistance.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Canoe.ca, a free news and entertainment portal operated by MediaQMI Inc. and owned by Sun Media Corp. prior to 2015, issued a public notice on September 2, 2017, informing users that certain databases containing records from 1996 to 2008 had been accessed without authorization. The notice explained that the breach was discovered shortly before the announcement and that an immediate investigation was launched to determine the scope and nature of the compromised information. According to the statement, the compromised databases held personal data belonging to approximately one million Anglophone and Francophone users who had interacted with the Canoe sites during the specified timeframe. The data had been collected through various user‑generated activities such as contest entries, forum participation, comment submissions, and the hosting of personal pages.

The investigation revealed that the exposed information included names, email addresses, mailing addresses, and telephone numbers, but contained no financial details such as credit card numbers or social insurance numbers. It was explicitly noted that no data collected after 2008 was affected by the breach, limiting the exposure to the historical records from the 1996‑2008 period. The organization emphasized that the breach did not involve any payment‑card or government‑identifier information, thereby reducing the risk of direct financial fraud for the affected individuals. The statement also clarified that the personal information had been provided voluntarily by users for the aforementioned site features.

In response to the incident, Canoe.ca engaged recognized data security experts to assist with a thorough investigation and to implement remediation measures aimed at securing the affected systems. The company reported that it had notified the Royal Canadian Mounted Police, the Office of the Privacy Commissioner of Canada, and all relevant provincial privacy commissioners about the security breach. Canoe.ca issued a sincere apology to its users and affirmed that it was making every effort to locate and contact every individual whose data might have been compromised during the illegal access. To facilitate user inquiries, the organization provided a toll‑free telephone number, 1‑833‑370‑2898, for anyone concerned about the breach to call for further information and assistance.

Sources

Sources available to members: 1 source.

CSIDB