← Canada Life

2026 Canada Life — Salesforce intrusion; ~70k confirmed vs 5.5M+ unverified forum sale (Apr–Jun)

2026 70.0K records affected Share on X

Data compromised

Names, addresses, dates of birth, gender, income band–style fields per Canada Life and journalism

Technical writeup

Canada Life publicly confirmed a cyber incident in April 2026 in which an unauthorized party accessed certain systems via a compromised employee account, with Insurance Business, The Globe and Mail, and Daily Hive reporting exposure of Salesforce-held fields for roughly seventy thousand individuals—often described as concentrated in one corporate benefits client cohort. In June 2026 Cybernews and Insurance Business reported a follow-on underground forum listing in which a threat actor claimed to be selling more than 5.5 million records allegedly tied to Canada Life; researchers described sample structures consistent with Salesforce CRM exports (names, emails, org metadata, permissions) while noting the sale figure remained unverified and materially larger than insurer-confirmed notifications—analysts characterize such gaps as extortion inflation. The insurer outlined containment, credit-monitoring offers, and regulatory engagement; parallel press discussed MFA phishing risk against SaaS consoles in the same ShinyHunters campaign wave as other financial institutions.

Root cause

Account compromise enabling Salesforce-oriented data access; criminal extortion claims in press

References