Annual report · First edition · September 2026 · Data as of March 31, 2026

Quebec Threat Landscape 2026

What four years of incidents reported to Quebec's Commission d'accès à l'information (CAI) reveal about the threat in Quebec, sector by sector.

583
incident notices received in 2025-2026 (514 in 2024-2025)
62.8%
of 2025-2026 notices involve a malicious cause (366 of 583)
21.3%
phishing or social engineering in 2025-2026, 11.5% in 2024-2025
17.7%
ransomware in 2025-2026, 21.6% in 2024-2025
01

Five key findings

In 2025-2026, phishing doubled in the incidents reported in Quebec. For the first time in four years, it outweighs ransomware.

More than six in ten reported incidents now cite an attack, and nearly nine in ten in manufacturing. Here are the five findings that matter, and what to do about them.

  1. ×2.1 phishing or social engineering, from 2024-2025 to 2025-2026
    Phishing becomes the second most reported cause.Notices citing phishing or social engineering rose from 59 to 124 in a single fiscal year, from 11.5% to 21.3% of notices. This is not a steady progression: the share was 12.8% in 2022-2023 and 8.3% in 2023-2024. The increase is therefore a one-year rise that will need to be confirmed. KPMG sees the same direction in its incident response work in Canada: business email compromise rose from 15% to 32% of its cases from 2023 to 2024.1
  2. 8 → 37 notices, from 2024-2025 to 2025-2026
    Intrusions in which data was viewed rose from 8 to 37 notices.These are the notices that report both a cyberattack and unauthorized access (“consultation non autorisée” in the register): 8 in 2024-2025, 37 in 2025-2026, from 1.6% to 6.3% of notices. This combination is consistent with an intruder who viewed data using valid access, but also with other scenarios, including a change in how notices are filled out. Section 05 separates what the register measures from what can be concluded from it. Outside the register, the Montreal firm Flare observes in its global data that the share of infostealer infections containing enterprise credentials more than doubled between early 2024 and late 2025.2
  3. 17.7% of notices cite ransomware in 2025-2026, 21.6% a year earlier
    Ransomware is declining, in number and in share.It fell from 111 to 103 notices. Among notices involving a malicious cause, its share dropped from 42.5% to 28.1%, after holding at around 39% in the first two fiscal years. Data theft, for its part, went from 19.0% to 17.3% of notices. KPMG also observes a decline in its incident response work in Canada: ransomware fell from 77% to 46% of its cases from 2023 to 2024.1 These series describe a change in the relative weight of causes, not an established replacement of one attack method by another.
  4. 91.5% of manufacturing notices involve a malicious cause, 25.9% in health care (four fiscal years combined)
    Sectors do not share the same incident profile.Over the four fiscal years combined, more than nine manufacturing notices in ten cite a malicious cause, versus one in four in health care, where error dominates. In 2025-2026 alone, the gap remains: 87.2% versus 32.5%. An organization is better served by locating its own sector than by calibrating on the Quebec average.
  5. 583 notices in 2025-2026
    Volume has more than doubled in four fiscal years, and growth is slowing.From 254 notices in 2022-2023 to 583 in 2025-2026, with annual increases of +75%, +16% and then +13%. The data cannot separate what is due to more incidents from what is due to better compliance with the reporting obligation.
02

Our recommendations

Five measures, in the order we would put them in place. They are our recommendations, not findings from the register: each responds to a measured finding, shown on the left, and aligns with the public recommendations of the Canadian Centre for Cyber Security. None requires an in-house security team; several can be entrusted to a service provider.

  1. ×2.1 notices citing phishing or social engineering, from 2024-2025 to 2025-2026
    Protect access with phishing-resistant authentication.Turn on multi-factor authentication for email and all remote access, management and suppliers included. Where possible, and at least for administrator accounts and remote access, favour a phishing-resistant method: a FIDO2 security key, a passkey or Windows Hello for Business. Then remove fallback methods, such as SMS, from those accounts: an attacker goes through the weakest method still registered. A second factor by code, SMS or push notification markedly reduces the risk, but it is not enough against “adversary-in-the-middle” phishing kits, which capture the session once authentication has succeeded.3 Even a second factor does not protect against a stolen session cookie, which opens a session without going through authentication again; infostealer logs contain them in large numbers, according to Flare's data presented in section 05.2 Being able to revoke open sessions, and knowing when the organization's credentials appear in these logs, completes the measure. Close unused accounts and manage passwords with a password manager.
  2. 42.9% of 2025-2026 notices citing a cyberattack give no other cause
    Know what you expose on the Internet.The register rarely says how the attacker got in. For an organization, though, it remains the first question to ask. Keep an inventory of what is reachable from outside, and keep it up to date: services, edge devices, subdomains of old projects, cloud accounts. In the investigations KPMG conducted in Canada in 2024, poor asset management (unknown accounts, unmanaged machines, shadow IT) emerged as a significant weakness in around 30% of cases.1
  3. 17.3% of 2025-2026 notices report data theft
    Prepare for a leak, not just an outage.Backups remain essential against encryption, but they do not address a data leak. Know what sensitive data you hold and where, what could leave in an intrusion, whom to notify and within what time frame. Quebec's Law 25 requires notifying the Commission and the individuals concerned when an incident presents a risk of serious harm; a procedure prepared in advance saves time.
  4. 13.4% of 2025-2026 notices cite unauthorized access
    Spot abnormal use of valid access.A sign-in made with a stolen password often goes unnoticed, because it looks like an employee's. Log sign-ins to important systems, get alerted to a sign-in at an unusual time or from an unusual location, and regularly review who has access to what. The same measure helps against abusive access by an insider. KPMG reports that logs were missing or overwritten in about half of its investigations, in 2023 as in 2024: without them, there is no way to know what an intruder viewed.1
  5. 1 supplier a dozen municipalities had to notify their residents (CodeRED, November 2025)
    Govern the suppliers that hold your data or your access.Know which ones, what they hold, and require by contract that they notify you of an incident within a set time frame. The register does not say whether an incident occurred at a supplier. The case of the CodeRED alert platform, presented in section 05, shows that a single incident at a service provider can force a dozen municipalities to notify their residents.4

What about training?

It remains useful. Errors or accidents appear in 25.9% of 2025-2026 notices, and awareness also helps people recognize phishing. It does not replace technical measures: it only takes one person being fooled once. That is why phishing-resistant authentication comes first.

By sector

Sectors where attacks dominate notices

Manufacturing, trade, construction, accommodation, professional services, transportation

  1. Start with the five measures above. They primarily target malicious causes, which dominate notices in these sectors.
  2. Focus on exposure and access. An inventory of what is reachable from the Internet, and phishing-resistant authentication on remote access.
Sectors where errors dominate notices

Health and social services, education, public administration

  1. Keep working on processes. Over four fiscal years, more than half of notices in these sectors cite an error or accident: recipients, transmissions, media.
  2. Tighten access rights. Over four fiscal years, 23.0% of public administration notices cite access abuse. Who can view what, and who checks?
  3. Track the malicious share. In education, it rose from 21.1% to 47.6% in two fiscal years, on small volumes. The five measures above apply here too.
03

SMEs in the data

In surveys, Quebec businesses often say they are ready, but most have no plan if ransomware strikes. The Commission's register does not record organization size, so this section draws on other sources and sets out what they can and cannot say about small and medium-sized businesses (SMEs).

Quebec had 1,024,273 active businesses in December 2025, including 278,816 with at least one employee. Of these, 72.0% have fewer than ten employees and 99.7% fewer than 500. The four sectors with the most employer businesses are construction (13.7%), retail trade (11.8%), health care and social assistance (11.3%) and professional, scientific and technical services (10.7%).5

Three of these four sectors are among those with the highest malicious share of notices over four fiscal years (section 04): construction 83.3%, retail trade 79.9%, professional services 73.1%. This comparison describes the incident profile of sectors where small businesses are numerous. It does not say that notices in these sectors come from SMEs, nor that a given SME faces a particular risk there. In health care, which mixes large public institutions and small clinics, the error-dominated profile may mostly reflect the large reporters; the register cannot verify this.

A Quebec-specific measure of incidence exists. Two researchers at the Université de Montréal analyzed Statistics Canada's cybersecurity survey for the roughly 2,800 Quebec businesses in its sample: 15.5% of them report experiencing an incident in 2023, versus 16.4% in 2021; the share of incidents aimed at stealing money or obtaining a ransom rose from 19.8% to 39.9%; and 44.9% of businesses have no employee assigned to cybersecurity.6

These figures cover only businesses with 10 or more employees, excluding public administration, like the entire survey.7 They therefore do not cover the 72% of Quebec employer businesses with fewer than ten. And having no employee assigned to cybersecurity does not mean no one handles it: across Canada, the reason most often cited by businesses without dedicated staff is relying on consultants or contractors (47%).

A KPMG survey of 154 Quebec businesses, in September 2023, gives a glimpse of their preparedness: 58% had no plan to deal with ransomware, 65% said they lacked the skilled staff to manage cybersecurity, and 74% felt their legacy systems made them vulnerable.8 These businesses all report more than $10 million in annual revenue, up to $1 billion: they are mid-sized firms, not the small businesses that make up most of Quebec's economy. The survey relies on an opt-in panel, with no published margin of error. Its rates of businesses “attacked” (63%) and having paid a ransom (60% over three years) are comparable neither with the register nor with the Statistics Canada survey, for lack of a common definition; we do not use them as a measure of the threat. The shortage of skilled staff, however, matches the IMC2 finding.

Two other surveys point the same way, with similar caveats. KPMG repeated the exercise in September 2024 with 350 Quebec businesses, larger still on average (47% report $500 million to $1 billion in revenue): 73% had no plan to deal with ransomware, and only 39% strongly agreed that cybersecurity is a priority for their business.9 The two samples differ too much to read a trend between 58% and 73%. On the SME side, the Quebec software publisher Devolutions has published a portrait since 2022. In the 2022 edition (151 IT professionals and decision-makers, a survey by the firm SOM), half of respondents said they had experienced a cyber incident in the past year, 54% had implemented two-factor authentication, and 18% had no formal policy for revoking former employees' access. In the 2024-2025 edition, 50% say they experienced at least one cyberattack in 2024; 71% say they are confident they could respond to a major incident, but only 13% consider their posture advanced, and 25% have no process for managing privileged access.10 These samples are small, recruited by a software publisher, and the size of the 2024-2025 sample is not published: they describe self-reported preparedness, not how often incidents occur.

What we draw from it. Large or small, the Quebec businesses surveyed often say they are confident, but few have a response plan or structured access management. This gap between confidence and preparedness underpins three of our recommendations: protecting access (1), preparing for a leak (3) and monitoring valid access (4).

04

Find your sector

Sector is the only information the register gives about the reporting organization. The gaps between sectors are clear: find yours to see which type of cause dominates the notices reported there.

Figure 4

Malicious share and error share, by sector

For each sector, share of notices citing a malicious cause (orange) and share citing an error or accident (blue). Four fiscal years combined, from the sector with the highest malicious share to the one with the lowest.

0%25%50%75%100%Manufacturing91.5%9.3%Wholesale trade85.4%4.9%Construction83.3%11.1%Accommodation and food services81.2%9.4%Retail trade79.9%10.7%Mining, oil and gas extraction77.3%13.6%Professional services73.1%20.6%Information industries67.3%23.1%Other services63.7%21.2%Transportation and warehousing62.5%18.8%Real estate and rental59.5%27.0%Arts, entertainment and recreation52.2%32.6%Finance and insurance45.8%30.2%Educational services31.1%59.8%Health care and social assistance25.9%56.6%Public administration23.0%52.2%
Malicious cause Error or accident
Base: CAI register, file AI-2627-216, 1,716 notices across the 16 sectors with at least 20 over four fiscal years. The other 44 notices (four sectors with fewer than 20 notices, and two notices with no sector from the official list) are not shown. Since a notice can carry several causes, the two shares do not add up to 100%.

Your sector at a glance

Business sector Notices (4 yrs) Dominant profile Malicious cause Error or accident Access abuse
Manufacturing 129 Attack 91.5% 9.3% 7.8%
Wholesale trade 41 Attack 85.4% 4.9% 12.2%
Construction 36 Attack 83.3% 11.1% 11.1%
Accommodation and food services 32 Attack 81.2% 9.4% 15.6%
Retail trade 149 Attack 79.9% 10.7% 13.4%
Mining, oil and gas extraction 22 Attack 77.3% 13.6% 13.6%
Professional services 223 Attack 73.1% 20.6% 10.8%
Information industries 52 Attack 67.3% 23.1% 25.0%
Other services 146 Attack 63.7% 21.2% 21.2%
Transportation and warehousing 32 Attack 62.5% 18.8% 12.5%
Real estate and rental 37 Mixed 59.5% 27.0% 13.5%
Arts, entertainment and recreation 46 Mixed 52.2% 32.6% 19.6%
Finance and insurance 275 Mixed 45.8% 30.2% 23.6%
Educational services 132 Error 31.1% 59.8% 12.9%
Health care and social assistance 251 Error 25.9% 56.6% 15.5%
Public administration 113 Error 23.0% 52.2% 23.0%

Base: CAI register, four fiscal years combined, 1,716 notices in the 16 sectors with at least 20. The last three columns are the share of the sector's notices citing at least one cause of that type; since a notice can carry several causes, they do not add up to 100%. “Attack” profile: at least 60% of notices cite a malicious cause. “Error”: the share of notices citing an error or accident exceeds the malicious share. “Mixed”: all other cases. These thresholds are ours.

In 2025-2026, the malicious share rises in four sectors

In education, health care, finance and public administration, the share of notices citing a malicious cause rises in 2025-2026. Volumes are small, from 29 to 94 notices per sector and fiscal year, and finance had already reached 53.6% in 2023-2024. These increases are a signal to confirm next year, not an established trend.

Figure 5

Malicious share in four sectors, by fiscal year

Share of the sector's notices citing at least one malicious cause, by fiscal year.

0% 20% 40% 60% 47.6%32.5%50.7%31.0% Education Health care Finance Public admin.
2023-2024 2024-2025 2025-2026
Base: CAI register, file AI-2627-216. Notices per fiscal year, 2023-2024 to 2025-2026: education 38, 37, 42; health care 55, 94, 83; finance 84, 88, 67; public administration 32, 30, 29.
05

What is changing in the reported causes

In 2025-2026, phishing became the second most cited cause in notices, ahead of ransomware. It is the first time in the four fiscal years.

Figure 2

Share of notices by family of reported causes

Share of the fiscal year's notices citing at least one cause from the family. Since a notice can carry three causes, it can count in several families.

0% 20% 40% 60% 62.8%Attack 25.9%Error 19.2%Abuse 17.3%Theft 2022-2023 2023-2024 2024-2025 2025-2026
Malicious attack Error or accident Access abuse Data theft
Show the data
Cause family 2022-2023 2023-2024 2024-2025 2025-2026
Malicious attack 55.5% 55.4% 50.7% 62.8%
Error or accident 30.3% 30.4% 35.1% 25.9%
Access abuse 9.2% 16.2% 16.1% 19.2%
Data theft 11.0% 13.1% 19.0% 17.3%
Base: CAI register, file AI-2627-216, 218, 444, 515 and 583 notices depending on the fiscal year (1,760 in total). The families are our groupings. Malicious attack: cyberattack, ransomware, phishing or social engineering. Error or accident: human error, accidental disclosure or communication, accidental destruction or use, loss, technical failure. Access abuse: deliberate unauthorized consultation, communication, disclosure or use. Theft: data theft.

Intrusions with data viewed: from 8 to 37 notices

In 2025-2026, 37 notices report both a cyberattack and unauthorized access, versus 8 a year earlier. This combination, rare until then, became the fourth most frequent in the register. It describes an intrusion during which data was viewed, and it deserves to be tracked. It does not, however, measure compromised accounts: the register says neither how the intruder got in nor whether credentials were stolen.

Figure 3

“Unauthorized access” reported with a cyberattack

Number of notices carrying both causes at once.

0 10 20 30 40 1 5 8 37 2022-2023 2023-2024 2024-2025 2025-2026 0.5% 1.1% 1.6% 6.3%
Base: CAI register, file AI-2627-216, 218, 444, 515 and 583 notices depending on the fiscal year. Broadening to all attack causes rather than cyberattack alone, the count rises from 2 notices in 2022-2023 to 45 in 2025-2026, or 7.7% of notices.

What the register measures

37 notices cite both a cyberattack and unauthorized access in 2025-2026, versus 8 in 2024-2025, 5 in 2023-2024 and 1 in 2022-2023. These 37 notices come from many sectors, with at most 6 in any one sector. Seventeen cite only these two causes, eleven add data theft, four add phishing. Over the same period, notices citing unauthorized access without an attack cause remained stable or declined: 39, 39 and then 33 from 2023-2024 to 2025-2026.

Our proposed interpretation

The combination describes an intrusion during which data was viewed. It is consistent with an intruder who used valid access, for example credentials obtained through phishing, to read what was accessible.

Other compatible scenarios

An intrusion through a vulnerability, followed by viewing of the data. Organizations that now describe the consequence of an intrusion as “unauthorized access,” through better knowledge of the categories or a change in instructions: cause vocabulary changes from one fiscal year to the next (section 06). Or several notices stemming from a single incident at a shared supplier, which the register cannot link.

What other sources describe

The Canadian Centre for Cyber Security detected more than one hundred “adversary-in-the-middle” phishing campaigns targeting Microsoft Entra ID accounts between 2023 and early 2025. These campaigns capture the user's session at the moment of sign-in, second factor included when it is not phishing-resistant.3 In France, ANSSI, the national cybersecurity agency, describes the role of credential-stealing malware (infostealers) and of brokers who resell access.11 In its incident response work in Canada, KPMG also reports business email compromise that bypasses multi-factor authentication.1 These mechanisms exist; the register cannot say what share of the 37 notices they explain.

What cannot be concluded

That these notices correspond to compromised accounts. What share of the increase stems from how notices are filled out rather than from the incidents. Nor that the increase will continue: it covers a single fiscal year.

What Flare sees, from Montreal

Flare, a Montreal threat intelligence company, monitors the logs of credential-stealing malware (infostealers) that circulate in the criminal ecosystem. In its February 2026 report, based on 18.7 million logs collected in 2025, the share of infections containing enterprise credentials (single sign-on or identity provider) rose from about 6% in early 2024 to nearly 14% by late 2025. Microsoft Entra ID appears in 79% of these logs, and 1.17 million of them contain both enterprise credentials and session cookies.2

What we draw from it. Flare's data are global and say nothing about Quebec in particular. Yet they describe the raw material of the scenario we propose for the 37 notices: valid access stolen in growing numbers, then used to view data. The register cannot say how many of the 37 notices stem from it; the two series point the same way.

Put another way: in 2025-2026, 74.1% of notices cite only attack, abuse or theft causes, with no error, accident or failure, versus 64.1% a year earlier. Conversely, notices citing only errors, accidents or failures fell from 31.3% to 20.8%.

Ransomware and data theft: a change in relative weight

Ransomware is cited in 47, 97, 111 and then 103 notices depending on the fiscal year. Its share of notices stays close to 21.6% for three fiscal years, then falls to 17.7% in 2025-2026. Among notices citing a malicious cause, its share went from 38.8%, 39.4% and 42.5% to 28.1%. Data theft went from 19.0% to 17.3% of notices the same year. These series show that ransomware weighs less among reported causes in 2025-2026. On their own, they do not show that attackers have replaced encryption with something else: the decline covers one fiscal year, and data theft is not rising in parallel.

Reported causes in detail, and their trend

Reported cause 2022-2023 2023-2024 2024-2025 2025-2026 Over 4 years One-year change
Cyberattack 33.5% 35.8% 31.3% 34.8% ▲ +3.5 pts
Phishing 11.5% 7.4% 9.7% 19.0% ▲ +9.3 pts
Ransomware 21.6% 21.8% 21.6% 17.7% ▼ −3.9 pts
Data theft 11.0% 13.1% 19.0% 17.3% ● −1.7 pts
Accidental disclosure 4.6% 12.8% 19.4% 15.3% ▼ −4.1 pts
Unauthorized access 7.8% 10.1% 10.7% 13.4% ▲ +2.7 pts
Human error 19.3% 13.7% 21.7% 13.0% ▼ −8.7 pts
Social engineering 1.8% 1.1% 2.9% 3.1% ● +0.2 pts
Technical failure 6.4% 3.6% 1.9% 2.9% ● +1.0 pts

Base: CAI register, 218, 444, 515 and 583 notices depending on the fiscal year. Share of the fiscal year's notices, causes ranked by 2025-2026; since a notice can carry up to three causes, columns exceed 100%. The change is in percentage points between 2024-2025 and 2025-2026: ▲ rising the cause is cited in a larger share of notices, ▼ falling in a smaller share, ● stable the gap is under two points. The “over 4 years” curve is scaled to each cause.

Volume: more than doubled in four fiscal years

From 254 notices in 2022-2023 to 583 in 2025-2026, growth is slowing: +75%, +16% and then +13%. The data cannot separate what is due to more incidents from what is due to better compliance with the reporting obligation.

Figure 1

Confidentiality incident notices received by the Commission

Quebec fiscal year, April 1st to March 31.

0 200 400 600 254 444 514 583 2022-2023 2023-2024 2024-2025 2025-2026 incl. 218 mandatory +75% +16% +13%
Base: official Commission totals, 1,795 notices over four fiscal years. Sources: annual activity and management reports (2022-2023 to 2024-2025) and register provided under file AI-2627-216 (2025-2026). The reporting obligation came into force on September 22, 2022: the 2022-2023 total includes 36 notices received before that date. Analyses of causes and sectors rest on a different base, the row-by-row register, totalling 1,760 notices (see section 06).

Before and after mandatory reporting

In 2021-2022, the last full year of the voluntary regime, the Commission received 78 reports. It described the incidents handled as follows: external intrusions 67%, human error 24%, other incidents 9%.12 These categories are not those of the register, and the organizations that reported voluntarily are not the same population as those reporting under the obligation. These 67% therefore cannot be compared with the 55.5% of notices citing a malicious cause in 2022-2023 as if they were the same measure. One can only note that, from 2022-2023 on, the mandatory register contains a large share of errors and accidents (30.3% of notices). The simplest hypothesis is that the obligation brings in incidents that were previously not reported; the data cannot verify it.

Other series help put the notice curve in context, without settling the question. Police-reported cybercrime in Quebec went from 4,004 incidents in 2018 to 11,902 in 2024, then 11,547 in 2025; more than half of police-reported cybercrime in Canada is fraud, mostly targeting individuals.13 At the federal level, where breach reporting has been mandatory since 2018, the Office of the Privacy Commissioner of Canada (OPC) receives a stable volume: 681, 693 and then 686 reports from 2022-2023 to 2024-2025.14 These observations are consistent with a Quebec increase driven partly by a recent reporting regime. They do not show how large that part is.

Public cases, for illustration

Method. We searched for incidents affecting Quebec organizations made public between April 1st, 2022 and September 23, 2026, in French and English, in the press, organizations' press releases and specialized sites. A case is included only if at least one consulted page confirms the facts; a figure that appears only in an inaccessible source is not used. The search produced thirty main cases and a dozen more in reserve. This review is not a representative sample: what becomes public depends on the organization's size, its public or listed status, and press interest. The nine cases below are illustrations, chosen to cover a range of sectors and situations. The last column is our reading, not a fact established by the source.

When Organization Facts reported by the source Our reading
Aug. 2022 BRP, Valcourt
Manufacturing
Ransomware. Head office and plant shut down for more than a week; about 30 GB stolen, including employees' passports and driver's licences.
InCyber, August 30, 2022
A production shutdown of more than a week is a cost in itself, regardless of any ransom.
Nov. 2023 Town of Lac-Mégantic
Public administration
Ransomware. All servers encrypted, backups included; data recovered in December with the help of outside firms.
La Tribune, Dec. 22, 2023
Backups reachable from the affected network can be encrypted along with everything else; an isolated copy reduces this risk.
May 2024 Pharmascience, Montreal
Manufacturing
Unauthorized access beginning in early May, discovered on June 1st, reported to the Commission on June 6. Employees' personal, financial and medical information exfiltrated.
Cyberswat, July 2024, citing the Commission
According to the source, about a month passed between the start of the access and its discovery.
Mar. 2025 Cablevision, Val-d'Or
Information industries
Exfiltration and sale of 66.8 GB: about 35,000 customers, banking data for fewer than one in ten; four years of credit monitoring offered.
Radio-Canada, March 18, 2025
The measures offered to affected customers, here four years of credit monitoring, are part of the cost of an incident.
Mar. 2025 Groupe Qualinet, Quebec City
Administrative and support services
Data theft with extortion, identity documents put up for sale; second incident after 2021; class action application filed.
Le Soleil, March 3, 2025; Droit-inc, March 11, 2025
An incident can lead to legal proceedings; here, a class action application.
Jul. 2025 Groupe Colabor, Saint-Bruno
Wholesale trade
Cyberattack on internal systems, disruptions until early August; employee data possibly compromised; Commission and police notified, credit monitoring for all employees.
Press release, August 7, 2025
The company made public the incident, its notifications to the Commission and the police, and the measures offered to employees.
Nov. 2025 Crisis24 (CodeRED), Montreal
Supplier to municipalities
Ransomware with data theft at the supplier; passwords compromised; about 6,000 Brossard residents notified, other cities too.
Le Courrier du Sud, Dec. 2, 2025
An incident at a supplier forces its clients to notify their own users.
Jan. 2026 CIUSSS du Centre-Sud-de-l'Île-de-Montréal
Health care
Error. A payroll file accidentally shared with about a hundred colleagues for more than six years; more than 20,000 current and former employees, with bank account numbers.
Radio-Canada, January 2026
A sharing error can last for years if file access rights are not reviewed.
Aug. 2026Outside the data period Commission de la construction du Québec
Construction-sector body
Ransomware with theft of client and employee information; online and phone services down until September 8; credit monitoring offered. Already hit in 2023 by the MOVEit vulnerability at a subcontractor.
CCQ, Sept. 4, 2026; CCQ, 2023
Businesses and workers can be affected by an incident at a body that holds their information, without having been attacked themselves.

Public cases are not part of any calculation in this report. The August 2026 case postdates March 31, 2026, the end of the period covered by the register. The numbers of people affected are those given by the open source; higher figures circulating in the press were not used for lack of a verifiable page.

Three observations concern this review itself. They do not generalize to all incidents.

Ransomware is common among public cases. Thirteen of the thirty main cases are ransomware, which halts operations and is visible from outside. Phishing is almost never named as the entry point in the sources consulted. For this cause, the register is the only measure available to us.

Public cases do not reflect the register's sector distribution. Nineteen of the thirty cases involve public bodies, health care or education, which issue press releases. We found no Quebec construction contractor, hotel or restaurant publicly named, even though these sectors are among those with the highest malicious share of notices. This gap shows what the review cannot see; it says nothing about these businesses' practices.

Eight of the thirty cases go through a third party: a subcontractor, a platform, a polling firm, a fundraising service provider. This proportion is a property of the review, not a measure of all incidents. It points to a question the register cannot address (section 07).

What other countries and other sources say

Reporting regimes differ in their threshold, categories and scope: their volumes and shares are not directly comparable, and no ranking is possible. Four comparisons nonetheless shed light on specific questions.

Do incident responders see the same shift? KPMG in Canada has published reviews of its incident response work for 2023 and for 2024. In its cases, the share of ransomware fell from 77% in 2023 to 46% in 2024, business email compromise rose from 15% to 32%, and unauthorized access and insider threats from 8% to 22%. KPMG also describes multi-factor authentication bypass and the use of Canadian VPN addresses to blend in with legitimate traffic.1 These figures cover KPMG's clients across Canada, by calendar year, and the number of cases is not published: they do not measure all incidents. Yet they point the same way as the register, through an independent method: less ransomware, more incidents that go through an account or an access.

Is ransomware declining elsewhere? In France, ANSSI writes in its Panorama de la cybermenace 2025 [Cyber Threat Landscape 2025] that “the number of ransomware attacks is slightly down compared with 2024,” while “the number of data exfiltration incidents known to ANSSI has increased significantly”: 128 ransomware compromises and 196 exfiltrations in 2025.11 In Canada, CIRA's annual survey shows the share of organizations reporting a successful ransomware attack falling from 28% in 2024 to 24% in 2025.15 Conversely, the Canadian Centre for Cyber Security notes that ransomware incidents brought to its attention have grown by an average of 26% per year since 2021.16 These sources do not measure the same thing. The decline observed in Quebec concerns the share of notices and a single fiscal year; it does not mean that ransomware groups are less active.

Is Quebec's malicious share unusual? In Australia, where reporting is also mandatory when there is a risk of serious harm, 59% of notifications in the first half of 2025 are attributed to a malicious or criminal attack.17 Quebec, at 62.8% in 2025-2026 by our grouping, is of the same order of magnitude. The two measures do not rest on the same categories.

Is unauthorized access rising elsewhere? At the federal level, the share of breaches reported to the OPC that are attributed to unauthorized access rose from 66% in 2022-2023 to 81% in 2024-2025.14 The federal category is broader than the combination studied above: it points the same way without confirming it.

06

Methodology and limitations

The figures in this report come from the register of confidentiality incident notices held by Quebec's Commission d'accès à l'information, obtained through an access-to-information request.18 A confidentiality incident, under Quebec's Law 25, is personal information accessed, used, disclosed or lost without authorization, whether through an attack or an error. One row per notice: the organization's sector and up to three causes, with no name or date. In total, 1,760 notices, from April 2022 to March 2026.

For 2025-2026, the register counts 583 notices. The Commission, whose annual report for that year has not yet been published, estimated 579 in June 2026; the gap is under 1%.19 The other sources cited in the notes serve to put these figures in context.

Five limitations to keep in mind

  1. We measure reports, not incidents.Only incidents that were detected, judged serious and reported appear in the register. The real number is higher, by an unknown margin.
  2. These data cannot explain the rise in volume.More incidents, better compliance with the obligation, or both: the register cannot tell. Statistics Canada, which surveys businesses with 10 or more employees, instead sees a decline in the share of affected businesses: 21% in 2019, 16% in 2023.7
  3. Causes are those the organization reports.They reflect its understanding of the incident, often in the heat of the moment, not an investigator's findings. The register never says how the attacker got in.
  4. “Cyberattack” is a very broad category.It does not distinguish a stolen password from an exploited vulnerability. In 2025-2026, 42.9% of notices citing it give no other cause.
  5. Categories shift from one fiscal year to the next.One cause disappears in 2025-2026, others appear partway through the series, and the Commission holds no written definitions. A change may therefore stem from how the form is filled out rather than from the incidents.

Reading the figures

Sector profiles combine the four fiscal years; changes compare 2024-2025 and 2025-2026. A “malicious cause” means a notice citing a cyberattack, ransomware, phishing or social engineering: this grouping is ours. Because a notice can carry three causes, percentages by cause add up to more than 100%.

Method details: validation, calculation bases, conventions

The recalculated counts were checked against the Commission's published figures: 444 rows for 444 notices in 2023-2024, 515 for 514 in 2024-2025; sector breakdowns match to within one unit. For 2025-2026, the five-year report of June 11, 2026 put forward an estimate of 579 notices, the compilation not being complete; the register, extracted on August 27, 2026, counts 583. The 2025-2026 annual report will settle the matter.

Figure 1 and the figure of 583 notices rest on the Commission's official totals; all analyses of causes and sectors rest on the row-by-row register. The two differ for two fiscal years.

Fiscal year Official total Register rows Explanation of the gap
2022-2023 254 218 The Commission provided only the notices received after the obligation came into force on September 22, 2022.
2023-2024 444 444 No gap.
2024-2025 514 515 One row more than the official total. The register carries no name or date, so the extra row cannot be identified. It is kept; percentages for this fiscal year are calculated on 515, which shifts them by at most 0.2 points.
2025-2026 583 583 No gap with the register. The Commission's five-year report puts forward an estimate of 579 (see above).
Total 1,795 1,760 Each figure and table states its own base.

Fiscal years run from April 1st to March 31; the Commission extracted its register on August 27, 2026, five months after the end of 2025-2026. A cause is counted once per notice. The average number of causes per notice went from 1.32 in 2022-2023 to 1.61 in 2024-2025, then 1.51 in 2025-2026: cause combinations depend partly on how notices are filled out. The cause “divulgation accidentelle” (accidental disclosure), cited 19 to 22 times a year until 2024-2025, no longer appears in 2025-2026. The public cases in section 05 run until September 2026 and are not part of any calculation.

The 20 sector categories used by the Commission are those of the North American Industry Classification System (NAICS).20 The register follows them in 97.7% of cases: 41 rows out of 1,760 carry a spelling variant or a subsector absent from the list. These discrepancies are concentrated in the first two fiscal years and then disappear, which makes recent years more reliable than the early ones.

07

Blind spots and recommendations to the Commission

Four pieces of information are missing from the register, and each one prevents a useful question from being answered.

Organization size. Nothing distinguishes an incident at a five-person SME from one at a 5,000-employee company. It is therefore impossible to say whether Quebec SMEs are over-represented.

The technical entry vector. The “cyberattack” category does not distinguish stolen credentials from an exploited vulnerability. This is what prevents direct measurement of account compromise (section 05). A category separating “compromised legitimate access” from “exploited vulnerability” would make it possible.

Third-party origin. The register does not indicate whether the incident occurred at a supplier. In our review of public cases, eight out of thirty went through a third party: the question arises, but nothing allows its scale to be measured. The CodeRED case shows how a single incident at a service provider ripples through to its clients.

The date. The register provided carries no incident or reporting date. Any analysis of seasonality, detection time or coordinated campaigns is out of reach.

Add to this a loss of transparency. On May 27, 2025, the Commission stopped publishing the list of organizations that reported an incident, while committing to continue releasing statistical data.21 The commitment has been kept, but the published statistics remain two separate breakdowns, with no cross-tabulation and no historical series.

We found no other comparable public series for Quebec. Quebec's Ministry of Cybersecurity and Digital Affairs publishes no count of the incidents handled by its network of cyber defence operations centres in its annual management reports.22 The Sûreté du Québec replied to two access requests, in 2023 and again in 2025, that its systems cannot isolate complaints related to cybercrime.23 We found no published results from the Institut de la statistique du Québec, Quebec's statistical agency, on incidents affecting businesses, and Statistics Canada does not publish a provincial breakdown of its survey.

Three recommendations to the Commission

  1. Publish the sector-by-cause cross-tabulation. The Commission holds this data, as its response to file AI-2627-216 shows. Publishing it annually would give each sector its own portrait.
  2. Publish the category definitions. The list of 20 business sectors exists and was provided to us. The causes, however, have none: the Commission replied that it holds no document defining them. Without written definitions, two organizations may classify the same incident differently, and the series loses comparability over the years.
  3. Add organization size and third-party origin to the form. These two fields would make it possible to measure directly the incidents reported by SMEs and the role of suppliers, which the current register cannot do.

What comes next: a survey of Quebec businesses

The Commission's register shows what organizations report. It does not say how large the organization is, how the attacker got in, or what stays below the reporting threshold. For the next edition, we want to add what is happening on the ground.

Over the coming months, and throughout the year, we will run an anonymous survey of Quebec businesses of all sizes, including the smallest ones, which no public survey covers today. It will run in short waves, each focused on one theme (access and authentication, incidents experienced, suppliers, preparedness), to gather precise information without asking for more than a few minutes at a time. Answers will never be linked to your identity or your business, and we will publish the questionnaire and the sample size with the results.

You can now ask to be invited to upcoming waves, to receive the 2027 edition by email when it comes out, or both. Your address will be used only for these emails: it will never be shared with third parties or used for sales outreach, and you will be able to unsubscribe in one click.

Notes and sources

  1. KPMG in Canada, Cyber Incidents and Intelligence: 2024, March 2025, pp. 5-7, and Cyber Incidents and Intelligence: 2023, April 2024, pp. 3 and 5. Reviews by KPMG in Canada's incident response team; the number of cases is not published. Documents removed from KPMG's website, cited from their archived copies. ↩
  2. Flare, Flare Research Warns 1 in 5 Infostealer Infections Could Yield Enterprise Credentials in 2026, news release, February 2, 2026, presenting the report 2026 State of Enterprise Infostealer Exposure: 18.7 million infostealer logs collected in 2025, global scope. The full report requires registration; the figures used here are those of the news release. ↩
  3. Canadian Centre for Cyber Security, Défense contre les attaques de type adversaire au milieu grâce à l'authentification multifacteur résistante à l'hameçonnage [Defending against adversary-in-the-middle threats with phishing-resistant multi-factor authentication], ITSM.30.031, October 2025. Resistant methods cited: FIDO2 security keys, passkeys, Windows Hello for Business. ↩
  4. Journal Métro, Fuite de données du système d'alertes CodeRED [CodeRED alert system data leak], November 28, 2025; CyberScoop, Crisis24 shuts down emergency notification system in wake of ransomware attack, November 26, 2025. ↩
  5. Institut de la statistique du Québec, Nombre d'entreprises actives au Québec [Number of active businesses in Quebec], December 2025 data. ↩
  6. Benoît Dupont and Jessica Roy, Institut multidisciplinaire en cybersécurité et cyberrésilience (IMC2), Université de Montréal, analysis of the Quebec data from the 2021 and 2023 Canadian Survey of Cyber Security and Cybercrime, as reported by Mon Carnet, September 21, 2026. The full report was not online as of September 23, 2026. ↩
  7. Statistics Canada, L'incidence du cybercrime sur les entreprises canadiennes, 2023 [The impact of cybercrime on Canadian businesses, 2023], Le Quotidien [The Daily], October 21, 2024. Canadian Survey of Cyber Security and Cybercrime. According to the note to readers, the target population comprises businesses with 10 or more employees, excluding public administration; 47% of businesses without dedicated cybersecurity staff cite relying on consultants or contractors. No provincial breakdown published. ↩
  8. KPMG in Canada, Cybercrime strikes more than six in 10 Quebec companies, news release, October 24, 2023. KPMG Private Enterprise Business Survey, Sago panel, August 30 to September 25, 2023: 700 Canadian businesses, 154 of them in Quebec, with $10 million to $1 billion in annual revenue, none under $10 million. Page removed from KPMG's website, cited from its archived copy. ↩
  9. KPMG in Canada, Focus Québec, 4th edition [in French], April 2025, pp. 24, 25 and 34. Survey of 350 owners or executives of Quebec businesses in September 2024, Sago panel; 13% of the sample reports less than $100 million in revenue. ↩
  10. Devolutions, Portrait de la sécurité informatique chez les PME québécoises [Portrait of IT security in Quebec SMEs], 2022, pp. 2 and 9-13 (web survey by the firm SOM, September 2021 to February 2022, 151 respondents), and 2024-2025 edition, 2025, pp. 2, 5 and 9 (sample size not published). ↩
  11. ANSSI, Panorama de la cybermenace 2025 [Cyber Threat Landscape 2025], CERTFR-2026-CTI-002, March 2026. ↩
  12. Commission d'accès à l'information, Rapport annuel d'activités et de gestion 2021-2022 [2021-2022 Annual Activity and Management Report], section 2.2.2.5. ↩
  13. Statistics Canada, tableau 35-10-0002-01, Cybercrimes déclarés par la police, par province [Table 35-10-0002-01, Police-reported cybercrime, by province], July 2026 release; breakdown of cybercrime according to Le Quotidien [The Daily], July 22, 2025. ↩
  14. Office of the Privacy Commissioner of Canada, Rapport annuel au Parlement 2024-2025 [Annual Report to Parliament 2024-2025] (686 reports, unauthorized access 81%) and annual reports 2022-2023 and 2023-2024 (681 and 693 reports; unauthorized access 66% in 2022-2023). ↩
  15. CIRA, 2025 Cybersecurity Survey, The Strategic Counsel, August 2025, 505 Canadian respondents, 9% of them in Quebec. ↩
  16. Canadian Centre for Cyber Security, Évaluation des cybermenaces nationales 2025-2026 [National Cyber Threat Assessment 2025-2026]. ↩
  17. OAIC, Data breach notifications increase to all-time high in 2025. ↩
  18. Commission d'accès à l'information du Québec, response to access request AI-2627-216, September 23, 2026. Registers of confidentiality incident notices, fiscal years 2022-2023 to 2025-2026. ↩
  19. Commission d'accès à l'information, Transparence et vie privée : protéger la démocratie à l'ère numérique [Transparency and privacy: protecting democracy in the digital age], five-year report, June 11, 2026, pp. 326-327 and notes 1180 to 1183. ↩
  20. Statistics Canada, SCIAN Canada 2022 version 1.0 [NAICS Canada 2022 Version 1.0]. The Commission provided no document defining its cause categories; it replied that it holds none. ↩
  21. Commission d'accès à l'information, Arrêt de la diffusion de la liste de déclarations d'incidents de confidentialité [Discontinuation of the list of confidentiality incident reports], May 27, 2025. ↩
  22. Ministère de la Cybersécurité et du Numérique [Quebec's Ministry of Cybersecurity and Digital Affairs], Rapport annuel de gestion 2024-2025 [2024-2025 Annual Management Report], October 7, 2025. The 2023-2024 report contains no incident count either. ↩
  23. Sûreté du Québec, response to an access request, March 17, 2025 (ref. 2502 468), repeating its response of October 24, 2023 (ref. 2309 610). ↩
A

Appendix: the 20 business sectors

The Commission classifies each reporting organization in one of the 20 sectors of the North American Industry Classification System. It publishes no definitions; the descriptions below summarize the scope of each sector as set out in Statistics Canada's NAICS 2022.

Sector Code What it covers
Agriculture, forestry, fishing and hunting 11 Farms, logging operations, fisheries and support services
Mining, quarrying, and oil and gas extraction 21 Mines, quarries, energy extraction and drilling services
Utilities 22 Generation and distribution of electricity, gas and water, wastewater treatment
Construction 23 General and specialty contractors, building, civil engineering
Manufacturing 31-33 Food processing, metals, wood, transportation equipment, pharmaceuticals
Wholesale trade 41 Sales to retailers, businesses or institutions, rather than to consumers
Retail trade 44-45 Sales to consumers, in store and online
Transportation and warehousing 48-49 Road, rail, air and marine transportation, couriers, warehousing
Information and cultural industries 51 Publishing, software, film, broadcasting, telecommunications, data hosting
Finance and insurance 52 Banks, credit unions, insurers, brokers, fund managers
Real estate and rental and leasing 53 Real estate brokerage and management, rental of housing, equipment and vehicles
Professional, scientific and technical services 54 Law and accounting firms, consulting engineering, architecture, advertising, IT, research
Management of companies and enterprises 55 Head offices and holding companies that manage other entities in their group
Administrative and support, waste management and remediation services 56 Employment agencies, call centres, private security, maintenance, waste management
Educational services 61 Schools, school service centres, CEGEPs, universities, vocational training
Health care and social assistance 62 Hospitals, clinics, long-term care homes (CHSLD), professional offices, child care and social services
Arts, entertainment and recreation 71 Performance venues, sports clubs, museums, parks, fitness centres
Accommodation and food services 72 Hotels, campgrounds, restaurants, bars, caterers
Other services (except public administration) 81 Repair and maintenance, personal care, funeral services, religious organizations, non-profits
Public administration 91 Government departments, public agencies, municipalities, police and protective services

Two consequences of this classification are worth keeping in mind. A sector can bring together very different organizations: health care covers a hospital centre as well as a two-person practice. And an organization is classified by its main activity, so a commercial Crown corporation does not appear under public administration but in its economic sector.