CSIDB logo
Incident

Canoe.ca

Incident posture

Attack window
Sep 1996
Location
Canada
Status
Unknown
CIA posture
Available to members
Updated
2026-08-29 03:44

Linked entities

Victim
Canoe.ca
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Canoe.ca, a free news and entertainment portal operated by MediaQMI Inc. and previously owned by Sun Media Corp., disclosed that databases holding user records were accessed without authorization. The investigation revealed that the compromised data included names, email addresses, mailing addresses and telephone numbers of roughly one million Anglophone and Francophone users, but contained no financial or social insurance information. Data gathered after the affected period remained secure, and the organization notified law enforcement and privacy authorities while working with security experts to address the breach. It apologized to users and stated it is attempting to contact those potentially affected, providing a telephone line for inquiries.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 2, 2017, Canoe.ca announced that it had learned of a security breach affecting databases containing user records from 1996 to 2008. The company stated that it immediately launched a thorough investigation after discovering the incident. The investigation found no evidence that the compromised data included financial information such as credit card numbers or social insurance numbers. The breach exposed personal information belonging to approximately one million Anglophone and Francophone users of the Canoe sites during that period.

The exposed data consisted of names, email addresses, mailing addresses, and telephone numbers that users had provided for contests, forums, comment pages, or the hosting of personal pages. Canoe.ca clarified that no data collected after 2008 was affected by the breach. The company emphasized that the compromised information did not contain any payment card details or government identifiers. The scale of the incident was described as affecting about one million users across both language communities.

Canoe.ca said it had taken all necessary steps to remediate the breach, working with recognized data security experts. It reported that it had notified the RCMP, the Office of the Privacy Commissioner, and all relevant provincial privacy commissioners about the security incident. The company apologized to its users and affirmed that it was making every effort to locate and contact those potentially affected by the illegal access to the 1996‑2008 data. Canoe.ca provided a telephone number, 1‑833‑370‑2898, for anyone concerned about the breach to call for information.

Sources

Sources available to members: 1 source.

CSIDB