Alert:
For more information on the cybersecurity incident, please visit the cybersecurity incident page.
Only some Canadian investors were impacted by the CIRO's cybersecurity incident. These FAQs apply only to those individuals.
If you received a letter from CIRO or an email from ciro@notifications.cyberscout.com they are legitimate and it is safe to follow the instructions.
1. Is this legitimate? Is this a scam?
2. What is CIRO?
3. Am I Affected?
4. If I am impacted, when will I receive notification?
5. Why did CIRO have my information?
6. How was my information compromised?
7. What should I do?
8. Does this mean I am the victim of identity theft?
9. Why wasn’t I contacted sooner?
10. Can I request that my information be deleted by CIRO?
11. What is CIRO doing to ensure this doesn't happen again?
12. Where can I get assistance or more information?
13. I received a letter saying I can "freeze" my credit. Why am I unable to do this in BC?
1. Is this legitimate? Is this a scam?
If you received a letter from CIRO or an email from ciro@notifications.cyberscout.com they are legitimate and it is safe to follow the instructions to register for free credit monitoring and identify theft protection through TransUnion and Equifax.
CIRO will not contact you by text message or through other social media, request access to any of your investment or bank accounts or that you provide information to facilitate access to these accounts, or request payment of any monies.
2. What is CIRO?
The Canadian Investment Regulatory Organization (CIRO) is the pan-Canadian self-regulatory body that oversees investment and mutual fund dealers in Canada. We have a regulatory mandate to protect investors from improper investment conduct and practices by providing oversight of Canadian investment and mutual fund dealers’ business conduct, including their trading activities.
3. Am I Affected?
Only some Canadian investors were impacted by the cybersecurity breach. Individuals impacted by the cyber incident were sent a notification letter by CIRO starting on January 14, 2026 and it may take several weeks for these letters to arrive.
If you received a notification letter from CIRO, then some of your information was impacted by the cyber incident. The notification letter describes the categories of your information that were impacted. We currently have no reason to believe that any of your information has been misused in any way. As a precaution, however, we are offering impacted individuals credit monitoring and identity theft protection services through TransUnion and Equifax to identify any potentially fraudulent use of your information.
4. If I am impacted, when will I receive notification?
Notification letters started to be sent on January 14, 2026. Notification letters were sent by email or regular mail through Canada Post. Please note that it may take several weeks for these letters to arrive.
5. Why did CIRO have my information?
Your information was obtained in the normal course of CIRO carrying out its mandate and conducting its investigative, compliance assessment and market surveillance work.
6. How was my information compromised?
In August 2025, CIRO identified a cybersecurity incident. We took immediate steps to contain the incident, secure our systems and protect the information in our care. We notified law enforcement and all relevant authorities including privacy commissions across Canada. Once contained, we retained a leading third-party forensic IT investigator to determine what information was impacted. After more than 9,000 hours of review, that investigation determined that a limited subset of investigative, compliance and market surveillance data, including some of investor information, was copied from our system.
We deeply regret that this occurred and apologize for any inconvenience or concern.
7. What should I do?
If you received a notice from CIRO, we recommend that you sign up for the free two-year membership in credit monitoring and identity theft protection services offered to you.
We also always recommend, as a matter of good practice, that you periodically review your investment accounts for any unusual activity and be vigilant about emails, text messages or phone calls asking you to provide sensitive information or to click on links or attachments, even if they appear to come from CIRO or someone you know or trust.
8. Does this mean I am the victim of identity theft?
We have been monitoring the dark web and currently have seen no indication that your information has been misused in any way. We are offering free credit monitoring and identity theft protection to impacted individuals as a further precautionary measure and to help detect possible misuse of your information.
9. Why wasn’t I contacted sooner?
We notified impacted individuals as soon as we determined that their personal information may have been impacted. CIRO is committed to protecting the security and confidentiality of the information entrusted to us, and we worked hard to notify impacted individuals as quickly as possible. The forensic investigation into the incident and the data exposed were very complex and required time to determine the impact and individual exposure.
10. Can I request that my information be deleted by CIRO?
CIRO will delete investor information when no longer required for its investigative, compliance assessment and market surveillance work, however we are unable to process individual deletion requests.
11. What is CIRO doing to ensure this doesn't happen again?
We take data security very seriously. This incident was the result of a sophisticated attack. In response to the specific features of this attack, we have taken several steps to enhance our data security practices. On an ongoing basis, we continue to look for ways to strengthen CIRO’s cybersecurity defences and to examine how we can collectively strengthen defences and cybersecurity best practices across the investment industry.
12. Where can I get assistance or more information?
13. I received a letter saying I can "freeze" my credit. Why am I unable to do this in BC?
While the letter mentioned the option to "freeze" your credit, this specific service is currently only available to residents of Quebec.
In British Columbia, the provincial government has passed the law to allow for credit freezes, but they have not yet set the date for when credit bureaus must have the service active. We apologize for providing instructions that cannot yet be completed in your province.
How can I protect myself today? Even though a "freeze" is not yet an option in BC, you can still take these three important steps:
August 28, 2025
CIRO systems access has been restored
August 18, 2025
CIRO detects cybersecurity threat
Welcome to CIRO.ca!
You can find the Canadian Investment Regulatory Organization (CIRO) at CIRO.ca with our fresh look and feel.