One-click check against public breach records. No account required.
Between 2017 and 2019, a Desjardins employee copied personal information belonging to members onto a shared network drive and eventually shared it externally. Names, addresses, dates of birth, Social Insurance Numbers, email addresses, phone numbers, and details of transaction habits were exposed for approximately 9.7 million individuals and businesses.
The federal Privacy Commissioner and Quebec regulator found Desjardins had inadequate access controls that let a single employee siphon data across multiple internal systems without detection for years. The incident is one of the most-cited insider-threat cases in Canadian financial services.
Reported impact: $201M CAD estimated response cost