Skip to content
FortaRisks
Back to blogThreat Intelligence

CCQ: fifteen days without services for an entire industry, and what the recovery teaches

September 14, 2026 · 5 min read

On Tuesday 8 September at 8:30 a.m., the Commission de la construction du Québec reopened its online and telephone services. They had been closed since Monday 24 August. Fifteen days during which the workers, employers and MÉDIC Construction policyholders of an entire industry had no access to the body that manages their competency cards, their hours, their insurance and their pension plan.

It is not the largest leak of the year. It is, for Quebec, the most complete example of an attack aimed at the operations of an organization that tens of thousands of businesses depend on without having chosen it. Here is the timeline, what the CCQ did well, and what it changes for your own plan.

The timeline, as the CCQ published it

Monday 24 August. Computer security incident. Online and telephone services are closed. The ccq.org website goes down.

Wednesday 2 September. The website comes back, with most forms accessible and an honest warning: some information may not be up to date. Online and telephone services stay closed "to allow a secure restoration". An emergency line stays open for MÉDIC Construction policyholders, and the CCQ keeps paying September pensions and handling medical emergencies abroad.

Friday 4 September. Two announcements the same day. In the morning, the CCQ publishes an update: analysis confirms that "certain" client and employee information was stolen. Affected people will be notified in writing and are offered Equifax credit monitoring with dark web surveillance, unusual-activity alerts, fraud support and identity-theft insurance up to one million dollars. The instruction: "you do not need to do anything right now". The same day, the Russian-speaking Qilin group claims the attack on its leak site and threatens to publish everything if no negotiation opens. According to La Presse, the records of 350,000 people are involved, administrative and medical files, dates of birth and social insurance numbers.

Tuesday 8 September. Full restoration of services, with a warning about longer than usual wait times.

Two points of context. The 350,000 figure comes from the press, not from the CCQ, which has communicated neither the exact nature of the data nor the number of people. And Qilin is not a stranger to the week: it is also one of the three groups Cisco Talos saw exploiting the Secure Firewall Management Center console, as we detailed in Friday's review.

Five lessons for your own organization

1. The outage costs more than the leak, and it is prepared beforehand

Fifteen days without services for a body of that size means hiring notices that do not go through, competency cards that do not renew, insurance claims that wait. What the CCQ got right, and what deserves copying, is the triage: September pensions were paid, medical emergencies abroad were handled, a phone line stayed open for policyholders. Those are the services whose interruption hurts someone, not merely the ones that inconvenience.

The question for you: if your systems close tonight for two weeks, which three services must you keep delivering, by what means, and who decides? If the answer is "we will see", you will not have it. That is the first blind spot described in our continuity plan that survives an attack.

2. Rebuild before reopening

The website came back on 2 September, the services six days later. That gap is not slowness, it is the mark of a restoration done properly: you do not reconnect systems on which an attacker had a fifteen-day head start without rebuilding them and rotating credentials. It is exactly what SonicWall, MikroTik and the European CERTs asked this week of customers whose edge equipment was compromised. A recovery plan that promises "back to normal within 48 hours" without planning for a rebuild promises something it cannot deliver.

3. Say what you know, dated, and say what to do

The CCQ's communication ticks the boxes that matter. Dated updates, published in one place. The theft confirmed as soon as it was established, without waiting for the full list. A clear instruction to affected people, even when the instruction is "nothing for now". And a concrete protection measure, paid for by the organization. It is also the behaviour Law 25 expects of any private organization facing an incident that presents a risk of serious injury: notify the Commission d'accès à l'information and the people concerned, and keep a register.

What that assumes on your side: a designated spokesperson, a release template already drafted, and a decision made calmly about the threshold at which you confirm a data theft.

4. You depend on bodies you did not choose

Your subcontractors, your suppliers and the joint industry body that manages your workers' cards were all in the same outage. On 7 September, another group listed EllisDon, one of the country's largest builders, on its leak site; the company has not confirmed and the claim remains an allegation. Two major construction players in one week, in Quebec and Ontario.

A third-party register that only contains the vendors you pay invoices to misses that dependency. Add the regulators, the sector platforms, the mandatory registries: the ones that stop you if they stop.

5. Same actor, same way in

Qilin exploits edge equipment. This week, a firewall management console; in previous weeks, VPN gateways. The chain of events that leads to fifteen days of downtime most often begins with an internet-facing device whose patches nobody was tracking. Your external attack surface is the first place to look, before the recovery plan.

Five actions for this week

  1. List the three services you must maintain if everything closes, and the degraded means for each. Name who decides to activate them.
  2. Check that your recovery plan includes rebuilding and credential rotation, with a realistic duration, not a 48-hour return.
  3. Draft now the release you would publish on day 1, day 5 and the day of recovery. Three templates, one spokesperson.
  4. Add to your third-party register the bodies and sector platforms whose outage stops you, even without a contract.
  5. Inventory your internet-facing edge equipment and the date of its last patch.

If you want to know where you stand on these five points before the next committee, our free cyber risk score places you in ten minutes across the resilience, third-party and vulnerability domains. To go further, the third-party risk module continuously tracks the dependencies you cannot choose.

Sources: CCQ, 4 September update · CCQ, website restored · La Presse, CCQ cyberattack · La Presse, a cyberattack paralyses CCQ services · Cisco Talos, Secure FMC exploitation · ransomware.live, Canadian victims

30 minutes to know what to fix first.

A member of our team walks you through FortaRisks on threats relevant to your sector, and you leave with your priorities. No chatbot.