Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

750,000 Impacted by Data Breach at Canadian Investment Watchdog

The incident impacted the personal information of CIRO member firms and their registered employees.

Data breach

The Canadian Investment Regulatory Organization (CIRO) this week revealed that hackers compromised the personal information of 750,000 individuals in an August 2025 cyberattack.

The data breach, CIRO says, was the result of a sophisticated phishing attack, and resulted in some systems being shut down. The incident did not impact the organization’s critical functions.

“We are confident that the incident is contained and that there is no active threat in ClRO’s environment,” the organization says.

CIRO disclosed the incident on August 18, saying that its preliminary investigation determined that “some personal information of member firms and their registered employees was affected”.

Now, the investment watchdog says the compromised personal information includes annual income, dates of birth, government-issued ID numbers, phone numbers, investment account numbers, social insurance numbers, and account statements.

“CIRO received this information in the normal course of carrying out its regulatory mandate to protect investors from improper investment conduct and practices, and through its investigative, compliance assessment and market regulation work,” the organization says.

Advertisement. Scroll to continue reading.

No passwords, PINs, or security questions were affected, as CIRO does not store such information.

The organization says it has no evidence that the compromised data has been misused, and that it has not identified threat activity or exposure on the dark web.

However, CIRO continues to monitor for malicious activity and is providing the impacted individuals with two years of free credit monitoring and identity theft protection services.

The organization started sending notification letters to the impacted clients and former clients of CIRO dealer members. It also published an FAQ page with additional information.

CIRO is a pan-Canadian self-regulatory body that provides oversight of the business conduct of investment and mutual fund dealers in Canada.

Related: Central Maine Healthcare Data Breach Impacts 145,000 Individuals

Related: Traveler Information Stolen in Eurail Data Breach

Related: Robo-Advisor Betterment Discloses Data Breach

Related: 22 Million Affected by Aflac Data Breach

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Jonathan Trull has joined Oracle as Global Head of Cyber Defense.

Plaid has appointed Sean Cassidy as Chief Information Security Officer.

Ann Barron-DiCamillo has been named Executive Vice President and Global Chief Information Security Officer at U.S. Bank.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.