Menu
Browse

Cyber Incident Victim: Qualinet

Date:

Oct 2025

Location:

Canada

Summary

Qualinet experienced a cyberattack in early winter that resulted in a data breach, prompting activation of its emergency plan and engagement of specialist teams to assess the scope. After initial analysis systems were restored though some data had been exfiltrated, affected clients were notified under Law 25, the case was transferred to Quebec City police and the Quebec Access to Information Commission, while executives expressed regret and urged broader business awareness of rising cyber threats.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

Early in the winter of 2024‑2025, Qualinet experienced a cyberattack that resulted in the theft of data from its systems. The company detected the breach and immediately activated its emergency response plan. A team of security specialists was mobilized to investigate the scope of the incident. Through their efforts, Qualinet was able to restore its operational systems quickly. The investigation confirmed that certain data had been exfiltrated during the attack.

Cyber Incident Image

In accordance with Quebec’s Law 25, Qualinet began the process of notifying affected clients about the data theft. Roger Vigneault, director of operations, stated that the company had been victim of a data theft despite having advanced security precautions in place. He emphasized that the disclosure was made in the interest of transparency and that Qualinet would continue to take all necessary protective measures. Éric Pichette, president of Qualinet, noted that many organizations treat cyberattacks as a taboo subject and explained his decision to go public to encourage broader awareness among business leaders. The case was handed over to the Service de police de la Ville de Québec for further investigation, and the Commission d’accès à l’information du Québec was also informed of the incident.

The theft of data triggered Qualinet’s legal obligations under Law 25, which requires organizations to implement governance rules for personal information and to inform individuals when their data is compromised. While the article does not specify the exact volume or type of data stolen, it confirms that some information was taken. Qualinet declined a request for an interview, limiting further public comment on the details of the breach. The incident aligns with a broader trend noted in a Canadian Internet Registration Authority survey from August 2024, which found that 44 percent of Canadian organizations reported having been victims of a cyberattack in the preceding twelve months.

Sources
Sources available to members
1 source