Biggest Cyber Attacks in Canada: 5 Lessons for Small Businesses
Some of the biggest cyber attacks in Canada since 2023 hit organizations most people deal with every week: a bookstore chain, a public library, a city government, a pharmacy chain, and a power utility. Each one was a ransomware attack, and none of the five organizations paid the ransom. The details, drawn from public reporting and official statements, carry lessons that apply just as much to a 20-person firm.
These are big names, but they are not outliers. Statistics Canada's 2023 Canadian Survey of Cyber Security and Cybercrime found that about 1 in 6 Canadian businesses (16%) were affected by cyber security incidents in 2023, and that spending on recovery doubled from about $600 million in 2021 to $1.2 billion in 2023.
Indigo, February 2023: Employee Records Are a Target
Indigo Books and Music's network was accessed with ransomware on February 8, 2023, according to the Financial Post. CBC News reported that a post claiming to be from the LockBit ransomware group threatened to publish the stolen personal data of current and former employees, and that Indigo refused to pay because it could not guarantee the money would not "end up in the hands of terrorists."
The lesson: payroll and HR files hold social insurance numbers, home addresses, and banking details. Many businesses lock down customer data and leave HR folders on a shared drive that everyone can open. Limit who can reach those files, and know where every copy lives.
Toronto Public Library, October 2023: Old Data Is Still Your Data
The Toronto Public Library was hit by ransomware on October 28, 2023. CBC News reported that files stolen from a server included names, birthdays, social insurance numbers, and home addresses of current and former employees of the library and its foundation "dating back to 1998." BleepingComputer confirmed the Black Basta ransomware operation was behind the attack. The library did not pay a ransom.
The lesson: records you no longer need still count when they are stolen. A retention rule, such as deleting former staff files after the legally required period, shrinks what an attacker can take.
City of Hamilton, February 2024: MFA Gaps Can Void Your Insurance
Hamilton's February 25, 2024 attack disabled roughly 80% of the city's network, according to Global News. The City of Hamilton said attackers got in through an external internet-facing server and demanded about $18.5 million. The city did not pay, and said it had spent $18.3 million on response and recovery through June 30, 2025.
The part every business should read twice: CBC News reported that the city's insurer covered none of its claims, totalling about $5 million, because a lack of multi-factor authentication was found to be "a root cause" of the breach. City staff had known about the MFA requirement in the policy since the fall of 2022.
The lesson: read the security conditions in your cyber insurance policy, then check that they are true today, not planned. If the application says MFA is on for all remote access and email, it needs to be on for all of it. Our explainer on cyber insurance for Canadian SMBs covers other cases where insurers challenged claims over MFA statements on the application.
London Drugs, April 2024: Plan for Operating Offline
London Drugs closed all 79 of its stores in British Columbia, Alberta, Saskatchewan and Manitoba after a cyber attack discovered on April 28, 2024, CBC News reported. Pharmacy staff stayed on site for urgent needs. BleepingComputer reported that LockBit later claimed the attack and said negotiations over a $25 million ransom had failed. London Drugs said it would not and could not pay.
The lesson: decide in advance how the business keeps serving customers if its systems are down for days. Who can take orders by phone? Which records do you need on paper? Our post on the real cost of cyber downtime breaks down the hidden costs, from lost revenue to idle staff and customers who do not come back.
Nova Scotia Power, 2025: Attackers Can Sit Inside for Weeks
The Office of the Privacy Commissioner's compliance letter lays out the timeline. Around March 19, 2025, an employee visited a compromised website and clicked a link in a pop-up, which installed malware. Around April 8, the attacker began moving across the network using accounts with domain administrator privileges. On April 25, it used harvested credentials to destroy backups and deploy ransomware. The OPC says about 375,000 current and 540,000 former customers were affected, and that the company did not pay a ransom.
SecurityWeek reported the company's initial notification count of about 280,000 customers. The final figure was much higher, which is common: the full scope of a breach is often not known for months.
The lesson: five weeks passed between the first infection and the ransomware. That is time in which someone watching the network could have spotted an intruder. Backups also need to be out of reach of the accounts an attacker is likely to steal. The Cyber Centre's guidance on backup and recovery is a good place to start.
What Do These Attacks Have in Common?
Each attack involved ransomware, data theft, or both, and in each case the organization refused to pay. Where the way in has been made public, it was ordinary: an internet-facing server and missing MFA in Hamilton, an employee clicking a pop-up at Nova Scotia Power. Neither required a rare or exotic technique, which is why the defences are also ordinary.
A short checklist drawn from these five cases:
- MFA on every remote access path and email account, with no exceptions left over from a pilot.
- Backups that a stolen administrator account cannot delete, tested by actually restoring something.
- Less sensitive data lying around, especially old HR and payroll files.
- A plan for running the business offline for several days.
- Someone watching for intruders, in-house or through a provider, so a five-week head start does not go unnoticed.
- An incident response plan that names who decides and who calls the insurer, police, and the Privacy Commissioner.
The question worth asking your IT lead this week: "If one of our staff clicked a fake update pop-up today, how long before anyone would know?" To see how your business measures against the Cyber Centre's 13 Baseline Controls, take our free cybersecurity assessment.
How prepared is your business?
Find out where you stand against Canada's 13 Baseline Cyber Security Controls. The assessment takes under 30 minutes and your answers stay in your browser.
Check Your ScoreFrequently Asked Questions
What were the biggest cyber attacks in Canada in 2023?
Two widely reported 2023 attacks were the LockBit ransomware attack on Indigo Books and Music in February, which exposed current and former employee data, and the Black Basta ransomware attack on the Toronto Public Library in October, which stole personal information of staff going back to 1998. Neither organization paid the ransom.
How much did the City of Hamilton cyber attack cost?
The City of Hamilton said in July 2025 that it had spent $18.3 million, through June 30, 2025, responding to and recovering from the February 2024 ransomware attack. Attackers had demanded about $18.5 million, which the city did not pay. CBC reported that the city's insurer covered none of its roughly $5 million in claims because multi-factor authentication had not been fully implemented.
How did attackers get into Nova Scotia Power?
According to the Privacy Commissioner of Canada's compliance letter, an employee visited a compromised website around March 19, 2025, and clicked a link in a pop-up, which installed SocGholish malware. The attacker later moved across the network with stolen administrator credentials and deployed ransomware on April 25, 2025, after destroying backups.
What can a small business learn from major Canadian cyber attacks?
The recurring lessons are practical: turn on multi-factor authentication everywhere, especially before an insurer asks; keep backups that attackers cannot reach; treat employee records as sensitive data; plan how the business keeps operating if systems go down; and have someone watching for intruders, since attackers often sit inside a network for weeks.
Cite This Page
Suggested citation:
Cybersecurity Canada (2026). Biggest Cyber Attacks in Canada: 5 Lessons for Small Businesses. Retrieved from https://cybersecuritycanada.ca/news/posts/biggest-cyber-attacks-in-canada-lessons-for-small-business/
Permanent URL: https://cybersecuritycanada.ca/news/posts/biggest-cyber-attacks-in-canada-lessons-for-small-business/ · Published September 14, 2026
Disclaimer: This article is intended for general informational purposes only and does not constitute professional cybersecurity, legal, IT, or compliance advice. While we strive to ensure accuracy, the cybersecurity landscape changes rapidly and information may become outdated. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation and develop appropriate security policies. Use of this information is at your own risk. See our Privacy Policy for more information.
Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.
How does your organization measure up?
Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential. Your answers never leave your browser.
Take the Free Assessment