Canada’s Canadian Investment Regulatory Organization (CIRO) confirmed a data breach affecting approximately 750,000 investors, attributing the incident to a sophisticated phishing attack detected in August 2025. CIRO said it conducted an extensive forensic investigation (citing 9,000+ hours of review by a third-party forensic firm) and determined that a limited subset of investigative, compliance, and market-surveillance data—including investor information—was copied from its systems; CIRO also reported that some systems were taken offline during response efforts but that critical operations were not disrupted.
CIRO warned that exposed data may include dates of birth, phone numbers, annual income, Social Insurance Numbers, government-issued ID numbers, investment account numbers, and account statements, while stating that login credentials were not at risk. The organization said it has no evidence of misuse and has not observed related dark-web exposure to date, and it reported notifying law enforcement and relevant authorities (including privacy commissioners) while offering affected individuals two years of credit monitoring and identity theft protection.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Starting January 14, 2026, CIRO began notifying confirmed affected individuals and offered two years of free credit monitoring and identity theft protection. CIRO also said it had notified law enforcement and privacy commissioners and reported no evidence of misuse or dark web exposure at that time.
On January 14, 2026, CIRO concluded an investigation spanning more than 9,000 hours and determined that approximately 750,000 investors were impacted. The review found that stolen data may include personal and financial information such as Social Insurance Numbers, government-issued ID numbers, and investment account details, while login credentials, PINs, and security questions were not affected.
On August 18, 2025, CIRO publicly announced the breach after detecting the threat the previous week. The organization said the incident affected some systems but did not disrupt critical operations.
On August 11, 2025, the Canadian Investment Regulatory Organization detected a cybersecurity threat later attributed to a sophisticated phishing attack. CIRO shut down certain non-critical systems, contained the incident, and began an investigation with third-party forensic support.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcerescana.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.