Canadian Data Breach Statistics
This reference collects current Canadian cyber incident and privacy breach figures from primary government sources. Cyber incidents affecting surveyed businesses, mandatory PIPEDA reports, federal Privacy Act reports, and affected accounts are related measures, but they are not interchangeable.
Key Canadian figures
Statistics Canada reported that 16% of Canadian businesses were affected by cyber security incidents in 2023. Total recovery spending reached $1.2 billion, double the amount reported for 2021. These survey results describe businesses in scope for the Canadian Survey of Cyber Security and Cybercrime, not every organization or every privacy breach.
- 16% of surveyed Canadian businesses were affected in 2023
- 30% of large businesses were affected
- Recovery spending reached $1.2 billion
- Scams and fraud affected 50% of impacted businesses
- Identity theft affected 31% of impacted businesses
- Ransomware affected 13% of impacted businesses
Canadian business cyber incidents in one chart
The panels keep their denominators separate: all surveyed businesses, affected businesses, and ransomware victims are different populations.
Ransomware and payment behaviour
Among businesses affected by cyber security incidents in 2023, more than one in eight reported ransomware. Most ransomware victims, 88%, reported that they did not make a ransom payment. Of those that paid, most reported less than $10,000, while a small share reported more than $500,000.
- Restoration, investigation, legal review, notification, downtime, and communication can exceed the demand
- Protected backups need regular restore tests
- Incident decision authority should be established before an attack
- Law enforcement, legal, insurance, privacy, and technical contacts should be documented
Reports to the federal privacy regulator
The Office of the Privacy Commissioner of Canada reported 686 private-sector PIPEDA breach reports and 613 federal Privacy Act reports for fiscal 2024-2025. The combined 1,299 reports were about 4% higher than the prior fiscal year, and 72% involved a real risk of significant harm.
- Provincial privacy regulators receive additional reports
- One report can affect one person, many people, or many accounts
- Mandatory reports are not a complete count of attempted attacks
- PIPEDA and Privacy Act figures cover different organizations
Affected people and accounts
Counts of incidents, reports, people, and accounts answer different questions. In fiscal 2023-2024, the OPC reported 693 private-sector breaches affecting about 25 million Canadian accounts. In fiscal 2024-2025, federal institutions reported 615 breaches affecting 309,865 individuals. These should not be added as though they measured the same population.
- An account count can exceed the number of unique people
- A report can cover several events or systems
- A survey incident can occur without a reportable privacy breach
- A privacy breach can result from error, loss, unauthorized access, or a cyber incident
Police reporting remains limited
Statistics Canada reported that 13% of affected businesses reported incidents to police in 2023, up from 10% in 2021. Reasons for not reporting every incident included resolving it internally, considering it too minor, or handling it with an IT consultant. Police data alone therefore cannot describe the full scale of business cyber incidents.
How businesses should use the data
Use national figures to support governance and budgeting, not to predict one organization’s exact probability or loss. A useful risk assessment starts with assets, business processes, likely threats, controls, dependencies, recovery needs, and the consequences of disclosure, alteration, or outage.
- Inventory systems, data, administrators, vendors, and backups
- Require strong authentication and separate privileged accounts
- Patch operating systems and applications
- Protect email, endpoints, cloud identities, networks, and remote access
- Prepare and exercise an incident response plan
- Keep protected backups and test complete recovery
Download and cite the Canadian breach data
This CSV keeps each figure beside its reporting period, unit, population and primary source so unlike measures are not accidentally combined.
Download the statistics as CSV
Suggested citation: North Star IT Services Ltd., Canadian Data Breach Statistics, updated August 19, 2026. This is a compilation of Statistics Canada and Office of the Privacy Commissioner figures; cite the linked primary source when reproducing an individual statistic.
The file may be reused with attribution. The underlying government statistics remain subject to their respective source terms.
Sources and methodology
Keep the reporting period, population, legal regime, and unit beside every statistic.
Common questions
How many Canadian businesses experienced a cyber incident in 2023?
Statistics Canada reported that 16% of Canadian businesses were affected by cyber security incidents in 2023 within the scope of its national business survey.
How much did Canadian businesses spend recovering?
Statistics Canada reported $1.2 billion in total recovery spending for 2023, double 2021. This is an aggregate estimate, not the average cost of one breach.
How many privacy breaches were reported federally?
For fiscal 2024-2025, the federal Privacy Commissioner reported 686 private-sector PIPEDA reports and 613 federal Privacy Act reports.
What share of affected businesses experienced ransomware?
Statistics Canada reported 13% of impacted businesses experienced ransomware in 2023, and 88% of those victims reported that they did not pay.
Are cyber incidents and privacy breaches the same?
No. A cyber incident can affect systems, operations, integrity, or money without creating a reportable privacy breach. A privacy breach can also result from error, loss, or unauthorized disclosure.
Turn the statistics into a response plan
North Star can inventory the environment, close baseline gaps, prepare the response workflow, and test recovery before a real incident.
Build an Incident Plan