Last updated 1 month ago
Canada Life, an insurance company, suffered a data breach in April 2026 as part of a 'pay or leak' extortion campaign by the ShinyHunters group. The breach was publicly disclosed when the group published the stolen data, which contained over 200,000 unique email addresses. The disclosure date is confirmed as April 2026, though the internal discovery date is not specified.
The attack vector was unauthorized access, with ShinyHunters exfiltrating a dataset including email addresses, names, phone numbers, physical addresses, and customer support tickets. The group subsequently published the data after an extortion attempt. No specific exploitation technique or CVE is mentioned.
Following the incident, Canada Life published an alert cautioning customers to be wary of phishing attacks, a common pattern after public release of breached data. The company also stated that only a small proportion of customers were impacted. No regulatory actions, litigation, or ransom payment details are mentioned.
Pay-or-leak extortion campaign by ShinyHunters group
Canada Life's breach underscores the need for robust access controls and monitoring to detect unauthorized data exfiltration by external threat actors like ShinyHunters. The exposure of customer support tickets suggests insufficient data minimization and segregation of sensitive information. The subsequent phishing alert indicates a failure to prevent credential theft or social engineering, highlighting the importance of multi-factor authentication and employee security awareness training.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor