How to Report a Cyber Attack in Canada: Where Your Business Should Go First
To report a cyber attack in Canada, most businesses file a report through the National Cybercrime and Fraud Reporting System, run by the RCMP's National Cybercrime Coordination Centre (NC3) and the Canadian Anti-Fraud Centre (CAFC), and contact their local police. If personal information was exposed, PIPEDA may also require a report to the Office of the Privacy Commissioner. In an emergency, call 911.
Knowing which door to knock on matters because each agency does something different. Police investigate. The CAFC and NC3 collect reports to link crimes. The Canadian Centre for Cyber Security gives technical advice. The Privacy Commissioner enforces privacy law. This guide explains when each applies, so the right calls go into your incident response plan before you need them.
Who Should a Canadian Business Report a Cyber Attack To?
Start with the Cyber Centre's Report a cyber incident page. It defines a cyber incident as "any unauthorized attempt, whether successful or not, to get into, change, delete, block access to, or shut down a computer system, network or account," and its short form asks who the incident affects, then tells you where to report. The usual destinations for a business are:
- Immediate danger or threat to life: 911 or local police.
- Ransomware, account takeover, fraud or other cybercrime: the National Cybercrime and Fraud Reporting System, plus local police.
- Large organization, critical infrastructure or government institution: the Canadian Centre for Cyber Security.
- Personal information exposed with a real risk of significant harm: the Office of the Privacy Commissioner of Canada, and the CAI if Quebec law applies.
- Non-criminal spam: the Spam Reporting Centre.
How Do You Report Cybercrime and Fraud to the RCMP and CAFC?
Report online at reportcyberandfraud.canada.ca. The CAFC's reporting page says victims and witnesses can report there, anonymously if they wish, and that the CAFC and NC3 share the information. The CAFC also takes reports by phone at 1-888-495-8501, Monday to Friday, 10 a.m. to 4:45 p.m. Eastern, closed on holidays.
The CAFC is clear about roles: "It's the role of your local police to investigate." The national system collects reports so that, in the CAFC's words, information "could link a number of crimes together, in Canada and abroad." For a business, that means filing both: the online report and a report to your local police service, which creates the file number your bank or insurer may ask for.
Have these details ready before you start:
- Dates and times of what happened, in order
- Email addresses, phone numbers, websites, account numbers or crypto wallet addresses used by the attacker
- Any payment details if money was sent (amount, method, receiving account)
- Screenshots, ransom notes or suspicious emails, kept in their original form
When Should You Contact the Canadian Centre for Cyber Security?
Contact the Cyber Centre when you want technical guidance, or when the incident affects a large organization, critical infrastructure or a government institution. The RCMP reporting system directs those organizations to "the Canadian Centre for Cyber Security." Any organization can use the Cyber Centre's online form to find the right reporting route.
The Cyber Centre's contact page lists 1-833-CYBER-88 (1-833-292-3788) and contact@cyber.gc.ca. The same page warns that the Cyber Centre does not make unsolicited phone calls to individual Canadians, so treat any "Cyber Centre" caller with suspicion and verify through those published numbers.
Do You Have to Report a Data Breach to the Privacy Commissioner?
Sometimes, yes. The Office of the Privacy Commissioner's guidance says organizations subject to PIPEDA must report breaches of security safeguards involving personal information "that pose a real risk of significant harm to individuals," notify affected individuals, and keep records of all breaches. The OPC confirms this applies to small businesses too.
Four details catch businesses out:
- The record-keeping duty covers every breach. The OPC says you must keep breach records for two years, even when you decide a breach did not need to be reported.
- Your provider's breach can still be your report. The OPC says that when personal information you transferred to a third-party processor is breached, it is reasonable to treat your organization as having control, and therefore the reporting duty. Check that your contracts require suppliers to tell you quickly.
- Individuals must hear from you quickly. The OPC says notification to affected individuals must be given "as soon as feasible" after you determine there is a real risk of significant harm, and must explain the steps they can take, such as changing passwords or monitoring accounts.
- Quebec has its own regime. Under Quebec's Law 25, organizations must notify the Commission d'accès à l'information and affected individuals promptly when a confidentiality incident presents a "risk of serious injury." Our Law 25 guide explains when it applies outside Quebec.
Whether a breach meets the threshold is a judgment call that depends on the sensitivity of the information and the probability of misuse. Get qualified privacy or legal advice for your specific situation.
Who Else Should You Tell After a Cyber Attack?
Beyond government reporting, three other calls usually belong in the first day:
- Your bank or payment processor, immediately, if money was sent or payment data was exposed. The OPC lists notifying a payment processor as an example of telling organizations that may be able to reduce harm.
- Your cyber insurer, if you have a policy. Our first 24 hours guide notes that many policies set short notification windows.
- Customers or partners whose data or systems may be affected, once you know enough to tell them something accurate.
What Should Go in Your Incident Response Plan?
Put the reporting contacts in writing now. The Cyber Centre's Baseline Controls start with incident response for a reason: under pressure, nobody remembers which agency does what. Your plan should name who makes each call, and list the CAFC, Cyber Centre, local police non-emergency line, bank, insurer and privacy contact. The incident response control page and our guide to building an incident response plan walk through the rest.
One question to ask your IT lead or provider this week: "If we were hit tonight, who would report it, to whom, and where is that written down?"
If you are not sure how ready your business is, our free cybersecurity assessment checks incident response alongside the other 12 Baseline Controls and gives you a prioritized list of what to fix first.
How prepared is your business?
Find out where you stand against Canada's 13 Baseline Cyber Security Controls. The assessment takes under 30 minutes and your answers stay in your browser.
Check Your ScoreFrequently Asked Questions
Where do I report a cyber attack against my business in Canada?
Most Canadian businesses report cybercrime and fraud online through the National Cybercrime and Fraud Reporting System at reportcyberandfraud.canada.ca, which is run by the RCMP's National Cybercrime Coordination Centre and the Canadian Anti-Fraud Centre. Contact your local police as well, and call 911 in an emergency. The Cyber Centre's online form can also tell you where to report.
Should a small business report a cyber incident to the Canadian Centre for Cyber Security?
You can. The Cyber Centre's Report a cyber incident page asks who the incident affects and points you to the right place to report. The RCMP reporting system directs large organizations, infrastructure operators and government institutions to report to the Cyber Centre. The Cyber Centre can be reached at 1-833-CYBER-88 or contact@cyber.gc.ca.
Do I have to report a data breach to the Privacy Commissioner of Canada?
Under PIPEDA, you must report a breach of security safeguards involving personal information to the Office of the Privacy Commissioner if it creates a real risk of significant harm to an individual. You must also notify affected individuals and keep a record of every breach for two years, whether or not it was reportable.
Can I report fraud or cybercrime anonymously in Canada?
Yes. The Canadian Anti-Fraud Centre says you can report a fraud or cybercrime online at reportcyberandfraud.canada.ca anonymously if you wish, whether you are a victim or a witness. The CAFC still recommends that victims contact their local police as soon as possible, because local police are responsible for investigating.
Cite This Page
Suggested citation:
Cybersecurity Canada (2026). How to Report a Cyber Attack in Canada: Where Your Business Should Go First. Retrieved from https://cybersecuritycanada.ca/news/posts/how-to-report-a-cyber-attack-in-canada/
Permanent URL: https://cybersecuritycanada.ca/news/posts/how-to-report-a-cyber-attack-in-canada/ · Published October 8, 2026
Disclaimer: This article is intended for general informational purposes only and does not constitute professional cybersecurity, legal, IT, or compliance advice. While we strive to ensure accuracy, the cybersecurity landscape changes rapidly and information may become outdated. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation and develop appropriate security policies. Use of this information is at your own risk. See our Privacy Policy for more information.
Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.
How does your organization measure up?
Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential. Your answers never leave your browser.
Take the Free Assessment