Skip to content

Canada's Business and Tech Newsroom

  • Professional Subscription
  • Partnerships & Advertising
  • Licensing & Syndication
Log In Subscribe
Welcome,
  • My Account
  • Log Out
  • Business
  • Tech
  • National
  • The Big Read
  • Briefings
  • Commentary
Search
Log In Subscribe
Welcome,
  • My Account
  • Log Out
Exclusive

Mackenzie Investments warns clients of data breach after cyberattack on a vendor’s vendor

A January hack into an American file-transfer service has exposed the private data of customers doing business with Canadian financial-services firms, showing how far-reaching a cyberattack on a company that provides basic internet plumbing can be.

Exclusive

Mackenzie Investments warns clients of data breach after cyberattack on a vendor’s vendor

‘It speaks to the complexity of the software supply-chains that companies, both small and large, are dealing with today’

By David Reevely and Leah Golob
Mackenzie Investments has warned its clients of a data breach after a cyberattack on a vendor’s vendor. Photo: Roberto Machado Noa/LightRocket via Getty Images
May 1, 2023
A A
A Small A Medium A Large
Share

Gift

Share

A January hack into an American file-transfer service has exposed the private data of customers doing business with Canadian financial-services firms, showing how far-reaching a cyberattack on a company that provides basic internet plumbing can be.

Mackenzie Investments, a unit of Power Corporation, is telling some customers that their personal information has been exposed, its vice-president of corporate communications, Nini Krishnappa, said in a statement to The Logic.

Talking Points

  • Some Mackenzie Investments clients’ data has been exposed in a cybersecurity breach that began with a U.S. file-transfer service used by one of Mackenzie’s vendors
  • The January GoAnywhere incident has affected dozens of firms and governments, and shows how far one hack to a link in the digital supply chain can go

“We were made aware that one of Mackenzie Investments’ third-party vendors, InvestorCOM, was compromised due to a cybersecurity incident related to a technology supplier to InvestorCOM, GoAnywhere,” Krishnappa wrote in an email. “After receiving notice from InvestorCOM, we took immediate steps to begin a full forensic investigation. Through our investigation, we recently discovered some personal information of current and some former investors was part of this incident.”

Mackenzie learned of the breach March 28 but only recently discovered some client information—which doesn’t include detailed financial data—was involved, he wrote.

InvestorCOM is a Toronto-based vendor of software for regulatory compliance in the financial sector in the U.S. and Canada.

On InvestorCOM’s website, the company boasts clients such as RBC Global Asset Management, CIBC, TD Bank, BMO, Desjardins, CI Assante Wealth Management, Canada Life, HSBC, Equitable Life of Canada and more.

Related Articles

Most Canadian cybersecurity breaches are to hold data for ransom: Study

By David Reevely

Cybersecurity bill gives ministers and regulators sweeping new powers

By David Reevely

InvestorCOM’s vice-president of marketing, Karen Makedon, directed The Logic to an online statement it posted after The Logic sent the company questions: “InvestorCOM recently became aware of a cybersecurity incident involving unauthorized access to the company’s systems related to GoAnywhere, the third-party software used for secure data transfers.” 

The statement did not say when exactly InvestorCOM discovered the cybersecurity incident nor did the company answer The Logic’s question regarding when. The statement did say that InvestorCOM immediately engaged a team of external cybersecurity experts to perform a forensic investigation and address the breach. 

Only InvestorCOM’s Secure File Transfer Protocol system was affected, which is hosted on the GoAnywhere application and is now contained, the statement said. 

“Certain information related to a small number of our Canadian clients was impacted by this incident,” the statement added. “We have notified all impacted clients and are working closely with them.”

The cascade began with a January breach of the file-transfer tool GoAnywhere, made by Fortra, a Minneapolis-based provider of a range of data security and digital infrastructure service. Fortra disclosed in early February that GoAnywhere had been hacked, kicking off weeks of reporting about one data breach after another.

Dozens of firms and organizations have been affected, including the City of Toronto, Investissement Québec and Onex. A ransomware group called Clop has claimed responsibility.

Fortra (which renamed itself from HelpSystems last November) reported the results of an investigation on April 17. It said the hackers had found a way to create user accounts for themselves in customers’ systems, allowing them access to those customers’ files.

What Clop got from the hack depended on what the affected customers used GoAnywhere to transfer. Because InvestorCOM used GoAnywhere, some of its clients’ data was involved; what that data was, in turn, depended on the client company’s dealings with InvestorCOM.

“I think it speaks to the complexity of the software supply chains that companies, both small and large, are dealing with today,” said Leigh Honeywell, the Ottawa-based CEO and co-founder of cybersecurity firm Tall Poppy. “One company’s breach may end up being collateral damage for another company’s nation-state-level targeting.”

Tall Poppy specializes in fighting online harassment, but Honeywell has previously worked in cybersecurity for Slack and Microsoft. She compared the GoAnywhere hack to another in January, in which a hacker cracked into the systems of U.S. telco T-Mobile, and from there got into Google’s Fi cellphone service, which uses T-Mobile under its hood.

The Logic requested comment from a number of reported InvestorCOM clients, including RBC Global Asset Management, CIBC Mellon, TD Bank, BMO, Desjardins, CI Assante Wealth Management, Canada Life, HSBC and Equitable Life of Canada. 

CIBC Mellon spokesperson Brent Merriman told The Logic in an email that there’s “nothing to report on our end.”

The firm uses InvestorCOM to support the “digital printing of certain financial-reporting documents published at the fund level,” but it does not share data or records about specific individuals or unitholders with it, he said.  

Desjardins declined to comment, while the rest of those contacted did not respond by deadline. 

After this story was published, Equitable Life spokesperson Patti McKague told The Logic the company is aware of the incident with InvestorCOM, but that “Equitable Life does not provide client information to InvestorCOM and, as a result, we’re not impacted by this.”

Meanwhile, Mackenzie has notified the office of the federal privacy commissioner of the hack. 

“Our office has received a breach report from Mackenzie Financial. We are reviewing the report and will be in communication with the company to obtain more information,” wrote Vito Pilieci, a spokesperson for privacy commissioner Philippe Dufresne, in response to emailed questions from The Logic.

InvestorCOM has not filed a report with the commissioner’s office, Pilieci added, but in general, the federal law on privacy and data protection puts the onus on banks, insurance companies and investment firms—they’re responsible for what happens to any private data they share with vendors, he said.

The federal Liberals’ Bill C-26 would give the government the power to impose cybersecurity obligations on federally regulated companies that operate digital systems it designates as critical infrastructure. Introduced last spring, the bill has completed second reading in the House of Commons, but has not yet been taken up by a committee for detailed scrutiny.

“I think companies who have that specific financial impact, there’s an increased duty of care—or at least, we should as a society be treating them as having an increased duty of care—to be vetting those vendors to be good stewards of people’s data,” Honeywell said.

Gift the full article

That can be extremely burdensome, she said; some of the largest companies will have tens of thousands of vendors.

“If you’re taking on the business risk of outsourcing, whatever the business function is that that software accomplishes, you have to understand what the security implications of that are. That is your duty as someone who is procuring software—to understand the security of the software that you’re procuring,” she said.

Editor’s note: This story has been updated to include information that Equitable Life of Canada provided after publication, and to reflect that Mackenzie said after publication that although customer data was exposed, the company has no evidence it was improperly taken. This story was also updated to reflect that Mackenzie uses InvestorCOM’s client communication services, not its software solutions.

#cybersecurity #data protection #fintech #InvestorCOM #Mackenzie Investments #Philippe Dufresne #privacy

Loading...

Thanks for sharing!

You have shared 5 articles this month and reached the maximum amount of shares available.

Close
This account has reached its share limit.

If you would like to purchase a sharing license please contact The Logic support at [email protected].

Close
Want to share this article?

Upgrade to all-access now

Close
Gift the full article!

You have gifted 0 article(s) this month and have 5 remaining.

Copy link and gift
Copy Link
Email to a friend
Send Email
Gift on Social Media

Recipients will be able to read the full text of the article after submitting their email address. They will not have access to other articles or subscriber benefits.

Photo: Roberto Machado Noa/LightRocket via Getty Images

Most Popular This Week

News

Bay Street backs Canada’s AI strategy, but warns the devil is in the details

By Anita Balakrishnan and Chaimae Chouiekh
A diptych showing Mark Carney on the left, and CIBC CEO Harry Culham on the right.
News

Diversifying trade requires banks to take bigger risks, official advised Carney before CIBC meeting

By Joanna Smith
The image shows the inside of Toronto Stadium on a sunny day. The rows of seats are empty; an empty green field is visible.
News

Toronto and Vancouver aren’t getting a World Cup bookings boom

By Chaimae Chouiekh
A yellow ambulance is pictured outside of a hospital in Montreal. A red sign in the foreground reads, “Urgence / Emergency.”
Commentary: Quebec Ink

Quebec just found out what not having digital sovereignty really means

By Martin Patriquin

In-depth, agenda-setting reporting

Great journalism delivered straight to your inbox.

News

Crypto firms are paying stablecoin rewards despite a looming federal ban

By Claire Brownell

Briefing

Canada to publish list of imports at risk of being made with forced labour

By Joanna Smith   |   Jun 12, 2026

TMX Group acquires RAFI Indices for $683M

By Anita Balakrishnan   |   Jun 12, 2026

Ikea invests in Toronto food startup NS/TX Industries’ US$10.5M fundraise

By Catherine McIntyre   |   Jun 12, 2026

Best business newsletter in Canada

Get up to speed in minutes with insights and analysis on the most important stories of the day, every weekday.

Exclusive events

See the bigger picture with reporters and industry experts in subscriber-exclusive events.

Membership in The Logic Council

Membership provides access to our popular Slack channel, participation in subscriber surveys and invitations to exclusive events with our journalists and special guests.

Recent Popular Stories

Commentary: Quebec Ink

Quebec just found out what not having digital sovereignty really means

By Martin Patriquin   |   Jun 8, 2026
A yellow ambulance is pictured outside of a hospital in Montreal. A red sign in the foreground reads, “Urgence / Emergency.”
News

OMERS investment chief departs for Singapore’s Temasek

By Chaimae Chouiekh   |   Jun 10, 2026
News

Diversifying trade requires banks to take bigger risks, official advised Carney before CIBC meeting

By Joanna Smith   |   Jun 9, 2026
A diptych showing Mark Carney on the left, and CIBC CEO Harry Culham on the right.
News

Canada’s surprise plan to buy Saab command jets leaves competitors seeking answers

By David Reevely   |   May 29, 2026
A closeup of a scale model of a jet covered in pixellated camouflage, with sensor equipment attached to the top of its fuselage. There are civilians and uniformed military personnel milling in the background.
The Big Read

We found every data centre in Canada

By Murad Hemmadi, David Reevely, Aleksandra Sagan, Chaimae Chouiekh, Martin Patriquin and Catherine McIntyre   |   Apr 8, 2026
Four vertical slices of aerial view photos. From left, a building in downtown Toronto housing several data centres, a picture of the Albertan wilderness where the proposed Wonder Valley data centre would go, a lit-up QScale data centre in Quebec, and a data centre at a Hydro-Quebec dam.
News

Toronto and Vancouver aren’t getting a World Cup bookings boom

By Chaimae Chouiekh   |   Jun 8, 2026
The image shows the inside of Toronto Stadium on a sunny day. The rows of seats are empty; an empty green field is visible.

Canada's most influential executives and policymakers are reading The Logic

  • CPP Investments
  • Sun Life Financial
  • C100
  • Amazon
  • Telus
  • Mastercard
  • bdc
  • Shopify
  • Rogers
  • RBC
  • General Motors
  • MaRS
  • Government of Canada
  • Uber
  • Loblaw Companies Limited
logic-logo

Canada's Business and Tech Newsroom

100% human-crafted journalism

Newsroom

  • News Tips
  • AI Policy
  • Editorial Disclosures
  • Story Pitches

Company

  • About Us
  • Terms of Service
  • Privacy Statement
  • Corporate Information

Contact

  • Contact Us
  • Advertise
  • FAQs
  • Work at The Logic

© 2026 The Logic Inc. All Rights Reserved.

Trusted by leaders

Error

Account creation failed.

Please email us at [email protected].

Create Account

[wppb-register form_name=”cozmo-registration-form-for-modal”]

I do have an account
Login
or

[wppb-login]

I don’t have an account