Cyber Security News

CIRO Confirms Data Breach – 750,000 Canadian Investors Have been Impacted

Approximately 750,000 Canadian investors were affected by a sophisticated phishing attack first disclosed in August 2025.

The self-regulatory organization announced the full extent of the breach on January 14, 2026. After completing a comprehensive forensic investigation spanning over 9,000 hours of examination.

The unauthorized access resulted from a targeted phishing campaign that compromised sensitive investor data held by CIRO in the course of its regulatory mandate.

The impacted information includes dates of birth, phone numbers, annual income figures, social insurance numbers, government-issued identification numbers, investment account numbers, and account statements.

CIRO emphasized that the organization did not collect account login credentials, such as passwords, security questions, or PINs, and therefore remained secure throughout the incident.

The breach affected only specific clients and former clients of CIRO dealer members. CIRO President and CEO Andrew Kriegler issued an apology, stating the organization is committed to supporting those personally affected.

While strengthening cybersecurity defenses and data security practices across the broader investment industry.

Response and Mitigation Measures

CIRO responded by immediately containing the incident and securing its systems upon discovery.

The organization engaged leading third-party forensic IT investigators and notified law enforcement agencies and relevant privacy commissioners.

The preliminary investigation initially revealed that registration information for member firms and registered individuals had been compromised, prompting immediate notification to affected parties.

As a precautionary measure, CIRO is providing impacted investors with two years of complimentary credit monitoring and identity theft protection services through both major credit agencies.

The organization reports no current evidence of information misuse and continues monitoring for malicious activity.

No threat activity or data exposure has been identified on the dark web as of the announcement date.

Affected investors began receiving notification letters from CIRO on January 14, 2026, with detailed instructions for activating protection services.

Individuals who believe they may have been impacted can verify their status through CIRO’s dedicated cyber incident webpage.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago