Canada Life employee-account data incident

Canada Life identified unauthorized access to certain applications through an employee account. The HIBP corpus associated with the incident contains contact, professional, and support-ticket data.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Canada Life identified unauthorized access to certain applications through an employee account. [2]

Impact

The HIBP corpus associated with the incident contains contact, professional, and support-ticket data. [1]

Documented data types include:

  • Employment information — Job titles listed for the HIBP incident corpus. [1]
  • Contact information — Email addresses, phone numbers, and physical addresses listed for the HIBP incident corpus. [1]
  • Customer service records — Support tickets listed for the HIBP incident corpus. [1]
  • Names — Names and salutations listed for the HIBP incident corpus. [1]

A cited record reports 237,810 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not Canada Life’s customer-impact count; as of 2026-05-13). [1]

Canada Life’s public assessment was that a small proportion of its customers may have been impacted; it did not publish an exact count in that statement. [2]

Timeline

  1. Documented event

    Incident date in the HIBP corpus; Canada Life’s public statement does not give a precise access timestamp or duration.

    [1]
  2. Public disclosure

    Publication date of Canada Life’s public cyber-incident statement.

    [2]
  3. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

Canada Life reported unauthorized access to certain applications through an employee account. [2]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Canada Life said it contained the incident, launched an immediate investigation with leading third-party cybersecurity experts, and notified authorities. Canada Life said affected people would be contacted directly and offered no-cost credit monitoring protection. Canada Life said regular operations and services continued after containment. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]