The Canadian financial cooperative said the information was illegally shared by an employee who has since been fired. Laval police notified the firm about the breach on June 14. Of those affected, 2.7 million were individuals, and 173,000 were business members. The data shared included first and last names, birth dates, social insurance numbers and banking habits; but passwords, security questions and PINs were not compromised. The organization said the incident was not a cyberattack, and its computer systems were not breached. In 2018, the group said it had over seven million members and clients. (The Logic)
Talking point: CEO Guy Cormier expressed regret over the incident at a press conference on Thursday, saying he felt “betrayed” by his former employee’s actions. The organization said it will pay for credit monitoring plans and identity theft insurance for 12 months for those affected. The incident is significant in its scope; Desjardins is North America’s largest federation of credit unions, and the breach affected around 40 per cent of its seven million clients, as of 2018. This incident is different from others because it didn’t come from a third-party hack, such as Facebook’s 2018 breach, which affected about 50 million accounts. Desjardins co-founded a Canadian cybersecurity collective in 2018 to protect users’ data from such threats; National Bank of Canada and Deloitte were also co-founders.