Canadian Investment Regulatory Organization
Incident posture
Linked entities
- Victim
- Canadian Investment Regulatory Organization
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
The Canadian Investment Regulatory Organization said hackers compromised personal information of 750,000 individuals through a sophisticated phishing attack that forced some systems offline while leaving critical functions unaffected. The exposed data included annual income, dates of birth, government‑issued ID numbers, phone numbers, investment account numbers, social insurance numbers and account statements, though no passwords, PINs or security questions were stored or affected. The organization stated there is no evidence of misuse and is providing affected individuals with free credit monitoring and identity theft protection, sending notification letters and publishing an FAQ. As a pan‑Canadian self‑regulatory body overseeing investment and mutual fund dealers, it continues to monitor for malicious activity.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In August 2025, hackers executed a sophisticated phishing attack against the Canadian Investment Regulatory Organization (CIRO), compromising the personal information of approximately 750,000 individuals. The breach led to the temporary shutdown of some of CIRO’s systems, although the organization stated that its critical functions were not affected. The compromised data included annual income, dates of birth, government‑issued ID numbers, phone numbers, investment account numbers, social insurance numbers, and account statements. CIRO emphasized that no passwords, PINs, or security questions were exposed because it does not store such information.
CIRO disclosed the incident on August 18, 2025, after a preliminary investigation determined that some personal information of member firms and their registered employees had been affected. The organization said it was confident the incident was contained and that there was no active threat remaining in its environment. CIRO reported that it had found no evidence that the compromised data had been misused and had not identified any threat activity or exposure of the information on the dark web. In response, CIRO began offering two years of free credit monitoring and identity theft protection services to all impacted individuals.
To inform those affected, CIRO started sending notification letters to the impacted clients and former clients of its dealer members and published an FAQ page with additional details about the breach. The organization continues to monitor for any malicious activity related to the compromised data. As a pan‑Canadian self‑regulatory body, CIRO oversees the business conduct of investment and mutual fund dealers in Canada.
Sources
Sources available to members: 1 source.