CSIDB logo
Incident

Canadian Investment Regulatory Organization

Incident posture

Attack window
Aug 2025
Location
Canada
Status
Resolved
CIA posture
Available to members
Updated
2026-08-27 02:34

Linked entities

Victim
Canadian Investment Regulatory Organization
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Aug 2025
Discovered
Undetermined
Disclosed
Aug 2025
Resolved
Undetermined

Summary

The Canadian Investment Regulatory Organization said hackers compromised personal information of 750,000 individuals through a sophisticated phishing attack that forced some systems offline while leaving critical functions unaffected. The exposed data included annual income, dates of birth, government‑issued ID numbers, phone numbers, investment account numbers, social insurance numbers and account statements, though no passwords, PINs or security questions were stored or affected. The organization stated there is no evidence of misuse and is providing affected individuals with free credit monitoring and identity theft protection, sending notification letters and publishing an FAQ. As a pan‑Canadian self‑regulatory body overseeing investment and mutual fund dealers, it continues to monitor for malicious activity.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In August 2025, hackers executed a sophisticated phishing attack against the Canadian Investment Regulatory Organization (CIRO), compromising the personal information of approximately 750,000 individuals. The breach led to the temporary shutdown of some of CIRO’s systems, although the organization stated that its critical functions were not affected. The compromised data included annual income, dates of birth, government‑issued ID numbers, phone numbers, investment account numbers, social insurance numbers, and account statements. CIRO emphasized that no passwords, PINs, or security questions were exposed because it does not store such information.

CIRO disclosed the incident on August 18, 2025, after a preliminary investigation determined that some personal information of member firms and their registered employees had been affected. The organization said it was confident the incident was contained and that there was no active threat remaining in its environment. CIRO reported that it had found no evidence that the compromised data had been misused and had not identified any threat activity or exposure of the information on the dark web. In response, CIRO began offering two years of free credit monitoring and identity theft protection services to all impacted individuals.

To inform those affected, CIRO started sending notification letters to the impacted clients and former clients of its dealer members and published an FAQ page with additional details about the breach. The organization continues to monitor for any malicious activity related to the compromised data. As a pan‑Canadian self‑regulatory body, CIRO oversees the business conduct of investment and mutual fund dealers in Canada.

Sources

Sources available to members: 1 source.

CSIDB