Canadian organizations frequently focus on whether to pay a ransom or how fast to recover, but the largest single line item in nearly every disclosed Canadian breach has been the post-incident class action settlement, not the ransom or the response.
Largest Canadian financial-services breach settlement to date. Roughly 9.7M Canadians affected by an insider data theft over 26 months (2017–2019). Court approved the settlement of
$200,852,500 maximum on June 14, 2022. Compensation: up to $90 per affected member; up to $1,000 if identity theft occurred after January 1, 2017.
Operational expenses incurred before the class action settlement: investigation, notification, customer protection programs, OPC investigation cooperation. Disclosed in Desjardins financial reports between 2019 and 2022.
8.6M Canadians had personal health information compromised in the 2019 cyberattack.
Settled for $4.9M guaranteed plus $4.9M contingent; valid claimants received $5.86 (cheque) or $7.86 (e-transfer). Joint Ontario / B.C. privacy commissioner investigation found LifeLabs failed to protect personal health information.
Ransomware attack on shared IT vendor TransForm Shared Service Organization.
516,000 patients and employees had personal health information compromised. Cancer radiation treatments transferred. Most systems offline until February 2024. Direct recovery and remediation costs only; class action exposure pending ($480M proposed action filed).
Direct expenses disclosed as of April 1, 2023; additional ransomware-related costs continued to accrue in subsequent quarters. The disclosed direct cost is dwarfed by the $26.5M Q4 revenue decline and $49.6M annual net loss attributable to the attack. Indigo refused to pay the ransom; attackers published stolen employee data.
Note on scale. The Desjardins settlement is approximately 20× the LifeLabs settlement, 27× the Ontario hospitals direct cost, and 38× the Indigo direct disclosed cost. Bars drawn to absolute proportional scale.
Bars to absolute scale · smallest case is 2.6% of Desjardins
What this means for your organization
The cost of getting incident response wrong is determined after the breach, by the courts, not by the attackers.
Most Canadian privacy commissioner investigations and class action proceedings come back to the same set of questions: were reasonable safeguards in place, was the breach detected and reported promptly, was the response proportionate. Each is the kind of question an effective security program answers in advance, not in deposition.