HomeResourcesCanadian Data Breach Statistics
Research reference · Updated August 2026

Canadian Data Breach Statistics

This reference collects current Canadian cyber incident and privacy breach figures from primary government sources. Cyber incidents affecting surveyed businesses, mandatory PIPEDA reports, federal Privacy Act reports, and affected accounts are related measures, but they are not interchangeable.

Key Canadian figures

Statistics Canada reported that 16% of Canadian businesses were affected by cyber security incidents in 2023. Total recovery spending reached $1.2 billion, double the amount reported for 2021. These survey results describe businesses in scope for the Canadian Survey of Cyber Security and Cybercrime, not every organization or every privacy breach.

  • 16% of surveyed Canadian businesses were affected in 2023
  • 30% of large businesses were affected
  • Recovery spending reached $1.2 billion
  • Scams and fraud affected 50% of impacted businesses
  • Identity theft affected 31% of impacted businesses
  • Ransomware affected 13% of impacted businesses
Shareable chart

Canadian business cyber incidents in one chart

The panels keep their denominators separate: all surveyed businesses, affected businesses, and ransomware victims are different populations.

Chart of Statistics Canada 2023 cyber incident figures: 16 percent of surveyed businesses and 30 percent of large businesses affected; among affected businesses, 50 percent reported scams or fraud, 31 percent identity theft, 13 percent ransomware, and 13 percent reported to police; 88 percent of ransomware victims did not pay.
Source: Statistics Canada, Canadian Survey of Cyber Security and Cybercrime, 2023. Read the primary release. Download the SVG chart or the source-labelled CSV.

Ransomware and payment behaviour

Among businesses affected by cyber security incidents in 2023, more than one in eight reported ransomware. Most ransomware victims, 88%, reported that they did not make a ransom payment. Of those that paid, most reported less than $10,000, while a small share reported more than $500,000.

  • Restoration, investigation, legal review, notification, downtime, and communication can exceed the demand
  • Protected backups need regular restore tests
  • Incident decision authority should be established before an attack
  • Law enforcement, legal, insurance, privacy, and technical contacts should be documented

Reports to the federal privacy regulator

The Office of the Privacy Commissioner of Canada reported 686 private-sector PIPEDA breach reports and 613 federal Privacy Act reports for fiscal 2024-2025. The combined 1,299 reports were about 4% higher than the prior fiscal year, and 72% involved a real risk of significant harm.

  • Provincial privacy regulators receive additional reports
  • One report can affect one person, many people, or many accounts
  • Mandatory reports are not a complete count of attempted attacks
  • PIPEDA and Privacy Act figures cover different organizations

Affected people and accounts

Counts of incidents, reports, people, and accounts answer different questions. In fiscal 2023-2024, the OPC reported 693 private-sector breaches affecting about 25 million Canadian accounts. In fiscal 2024-2025, federal institutions reported 615 breaches affecting 309,865 individuals. These should not be added as though they measured the same population.

  • An account count can exceed the number of unique people
  • A report can cover several events or systems
  • A survey incident can occur without a reportable privacy breach
  • A privacy breach can result from error, loss, unauthorized access, or a cyber incident

Police reporting remains limited

Statistics Canada reported that 13% of affected businesses reported incidents to police in 2023, up from 10% in 2021. Reasons for not reporting every incident included resolving it internally, considering it too minor, or handling it with an IT consultant. Police data alone therefore cannot describe the full scale of business cyber incidents.

How businesses should use the data

Use national figures to support governance and budgeting, not to predict one organization’s exact probability or loss. A useful risk assessment starts with assets, business processes, likely threats, controls, dependencies, recovery needs, and the consequences of disclosure, alteration, or outage.

  • Inventory systems, data, administrators, vendors, and backups
  • Require strong authentication and separate privileged accounts
  • Patch operating systems and applications
  • Protect email, endpoints, cloud identities, networks, and remote access
  • Prepare and exercise an incident response plan
  • Keep protected backups and test complete recovery
Reusable data

Download and cite the Canadian breach data

This CSV keeps each figure beside its reporting period, unit, population and primary source so unlike measures are not accidentally combined.

Download the statistics as CSV

Suggested citation: North Star IT Services Ltd., Canadian Data Breach Statistics, updated August 19, 2026. This is a compilation of Statistics Canada and Office of the Privacy Commissioner figures; cite the linked primary source when reproducing an individual statistic.

The file may be reused with attribution. The underlying government statistics remain subject to their respective source terms.

FAQ

Common questions

How many Canadian businesses experienced a cyber incident in 2023?

Statistics Canada reported that 16% of Canadian businesses were affected by cyber security incidents in 2023 within the scope of its national business survey.

How much did Canadian businesses spend recovering?

Statistics Canada reported $1.2 billion in total recovery spending for 2023, double 2021. This is an aggregate estimate, not the average cost of one breach.

How many privacy breaches were reported federally?

For fiscal 2024-2025, the federal Privacy Commissioner reported 686 private-sector PIPEDA reports and 613 federal Privacy Act reports.

What share of affected businesses experienced ransomware?

Statistics Canada reported 13% of impacted businesses experienced ransomware in 2023, and 88% of those victims reported that they did not pay.

Are cyber incidents and privacy breaches the same?

No. A cyber incident can affect systems, operations, integrity, or money without creating a reportable privacy breach. A privacy breach can also result from error, loss, or unauthorized disclosure.

Turn the statistics into a response plan

North Star can inventory the environment, close baseline gaps, prepare the response workflow, and test recovery before a real incident.

Build an Incident Plan