August was not quiet in Quebec and Ontario. Six documented incidents in four weeks, across construction, ticketing, finance, healthcare, technology and the non-profit sector. Taken one at a time, each looks like another news item. Put side by side, they produce five specific findings, and those findings translate into concrete actions for a risk owner.
The facts first, the findings after.
What happened
Quebec
Commission de la construction du Québec, August 24. The CCQ's online and phone services have been down since the morning of Monday, August 24 because of a cyberattack. The organization, which serves close to 200,000 construction workers, shut down its systems preemptively at the first signals and brought in external experts. As of August 27, the service interruption notice was still posted and the CCQ could not confirm whether any data had been compromised.
xPayrience (Projex Media), intrusion July 11, revealed August 18. A file circulating on the dark web holds the information of roughly 413,935 customers of this Magog-based ticketing platform: names, emails, phone numbers and full addresses, plus details of 476,000 tickets sold and 402,000 accommodation bookings. No banking data, no social insurance numbers. The affected client organizations are well-known names: Foresta Lumina, ComediHa!, the Chicoutimi Saguenéens, the Val-d'Or Foreurs, the Grand Prix Ski-Doo de Valcourt. A security researcher, Stéphane Auger, downloaded and analyzed the file. As of August 19, according to the company's president, Quebec's privacy regulator had still not been notified.
Senvest Capital, August 19. The extortion group TheGentlemen claimed an attack against the investment firm headquartered in Montreal and New York, threatening to publish the data. The claim has not been confirmed by the company to date.
Ontario
Waterloo Regional Health Network, investigation still open in August. The hospital network was notified on February 6, 2026 by OntarioMD of an incident affecting its connection to the Health Report Manager, the Ontario Health-hosted tool that sends hospital care information to a patient's primary care provider. The potentially exposed information covers care received by 150,000 people between April 2025 and January 2026. Ontario's Information and Privacy Commissioner is still investigating six months after being notified, and has opened dedicated phone lines for concerned patients.
MOSAID Technologies, August 16. The Ottawa technology company was claimed by the Qilin group on its leak site.
Canadian Mental Health Association, August 14. The organization, headquartered in Toronto, was claimed by the Storm group, with an estimated attack date of August 11. An emerging group, so the claim should be treated with caution until confirmed.
Finding 1: in half the cases, the organization affected is not the one that was attacked
The festivals, junior hockey teams and campgrounds whose customers sit in the xPayrience file were not hacked. Their ticketing provider was. The Waterloo Regional Health Network was not hacked either: the incident hit OntarioMD and the provincial report transmission tool. In both cases, the organization that has to explain the situation to its customers or patients is not the one that suffered the intrusion.
This is exactly the pattern we described with Ceva Logistics and Wesco, repeating here at a local scale, among mid-sized organizations with no dedicated security team.
What it means: your vendor inventory must separate the vendors holding your customers' information from those holding only yours. A ticketing platform, a payroll provider, a booking tool: these are custodians of your customers' data. If they go down, your name is on the notification letter.
Finding 2: nobody learned it from their vendor
The xPayrience file was surfaced by a security researcher who found it on the dark web, 38 days after the intrusion. The claims against MOSAID, Senvest and CMHA come from criminal groups' leak sites, not from the companies. In last year's Ontario Health atHome case, it was the parliamentary opposition and the press that broke the story.
Today's default disclosure channel is neither the vendor nor the regulator. It is the criminal group's leak site, or a researcher downloading a file.
What it means: if your third-party monitoring rests on "our vendor will tell us", you will learn about the incident at the same time as your customers. Monitoring leak sites and data dumps, against a named list of your critical vendors, is no longer a large-enterprise luxury. It is precisely what a threat intelligence capability does when it is fed by your third-party register rather than a generic feed.
Finding 3: the delay is the real problem, not the breach
Look at the dates. xPayrience: intrusion July 11, public discovery August 18, regulator not notified as of August 19. Waterloo: notification from OntarioMD on February 6, commissioner's investigation still open at the end of August. Quebec's Law 25 requires reporting any incident presenting a risk of serious injury "with diligence", and keeping an incident register. Thirty-eight days during which a file on 414,000 people circulates without anyone knowing is not a documentation problem. It is a wide-open window for targeted phishing and fraud.
What it means: your response plan must be timed, not merely documented. How many hours between detection and the decision to notify? Who decides? Who drafts? The question to put to your team this week: if a vendor notifies us at 4 p.m. on a Friday, who makes the notification call, and against what written criterion?
Finding 4: availability is the visible harm, confidentiality is the question people ask
The CCQ illustrates the gap perfectly. What the public sees is 200,000 construction workers cut off from online and phone services for four days, in peak season. What reporters ask is "was data compromised?". Both matter, but they are managed in different places: the first belongs to the business continuity plan and recovery targets, the second to Law 25 and the incident register.
Note the CCQ's decision as well: shutting systems down at the first signals on Monday morning. That is a sound containment call, and it carries an immediate, visible operational cost. If nobody has pre-authorized that trade-off in your organization, your team will make it under pressure, at 6 a.m., without a clear mandate.
What it means: your plan must answer two distinct questions. How long can we operate without this system, and who has the authority to pull the plug?
Finding 5: the regulator's public register is no longer a monitoring source
Since May 2025, Quebec's privacy commission has stopped publishing the names of businesses and public bodies that report a confidentiality incident. It still releases quarterly statistics, but no names. The rationale is defensible from the standpoint of protecting affected individuals and of organizations still managing an incident.
For a third-party risk manager, the consequence is blunt: you can no longer consult an official list to find out whether one of your vendors reported an incident in Quebec. The most current public source on your vendors has become the press, leak sites and independent researchers.
What it means: this information now has to come from your contracts. An incident notification clause with a stated deadline, applying to any incident touching your data or your customers' data, whether or not there is a "risk of serious injury" in the legal sense. Without that clause, you depend on someone else's goodwill and communications calendar.
What to do this week
Five actions, in order, doable by a team with no security department.
- Pull the list of vendors that hold your customers' data. Not every vendor: those ones. Ticketing, payroll, booking, newsletter, customer service, hosting. A spreadsheet is enough to start.
- For each one, record the contract's notification clause. Does it exist? Does it state a deadline? In practice, most small-business contracts have none. That is the first thing to fix at renewal.
- Name an owner per critical vendor. A person, not a department. That is who picks up the phone when a name shows up on a leak site.
- Time your notification decision. A one-hour session, a simple scenario: a vendor notifies us, what happens in the first 72 hours, and who signs off? Write the answer down.
- Put your critical vendors under monitoring. Alerts on the names, leak-site watch. If you are not doing it in house, that is the job of a threat intelligence service wired into your third-party register.
Two resources to go further: our free vendor security questionnaire and the guide to building a third-party risk management program. If your exposure is mostly about personal information of Quebec residents, our Law 25 readiness check shows your gaps on notification, register and contracts in ten minutes.
August's six incidents share one more trait: none was technically spectacular. These are ordinary organizations, with ordinary vendors, that discovered their exposure through a third party. That is the most likely version of your own next incident.
Sources: La Presse, cyberattack at the CCQ · CCQ, service interruption notice · Dernière Heure QC, xPayrience leak · CBC, Ontario commissioner's investigation into Waterloo · WRHN, notice of security incident · Ransomware.live, Canadian victims · La Presse, the CAI stops publishing names · CAI, incident declaration disclosures