[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fpfcnctay1rzg":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":13,"affectedCountUnit":23,"hasEnglishDescription":4,"contentLocale":24,"availableLocales":25,"translations":27,"severity":30,"dataClasses":31,"description":39,"seoTitle":40,"seoDescription":41,"logoUrl":42,"isVerified":4,"isSensitive":43,"isSpamList":43,"isMalware":43,"company":44},"6a452308a20f867c8ba8e767","Canada Life","Canada Life Data Breach","canada-life","canadalife.com","2026-04-20T00:00:00.000Z","2026-05-13T06:51:17.000Z",null,"2026-07-02T04:54:07.177Z","2026-07-19T00:03:15.581Z","Insurance customer support data breach","https:\u002F\u002Fwww.canadalife.com\u002Fabout-us\u002Fnews-highlights\u002Fnews\u002Fcanada-life-recently-identified-a-cyber-incident.html",[17,19,20],"https:\u002F\u002Fwww.canadalife.com\u002Ffraud-prevention\u002Fsuspicious-communications.html","https:\u002F\u002Fwww.breachsense.com\u002Fbreaches\u002Fcanada-life-data-breach\u002F",237810,"known","unknown","en",[24,26],"tr",{"en":28,"tr":29},{"slug":9},{"slug":9},"High",[32,33,34,35,36,37,38],"Email addresses","Job titles","Names","Phone numbers","Physical addresses","Salutations","Support tickets","\u003Cp>The Canada Life data breach is an incident recorded on April 20, 2026, involving the publication of customer communication and support data used in the context of insurance and financial services. The verified searchable scope in this record is 237,810 unique email addresses. The verified data classes are email addresses, job titles, names, phone numbers, physical addresses, salutations, and support requests.\u003C\u002Fp>\n\u003Cp>The company stated that the proportion of customers who may have been affected by the incident is small and warned its customers against phishing attempts after the data was published. This record does not claim that passwords, payment cards, bank accounts, social security numbers, insurance policy numbers, or full financial account information were leaked. The main source of risk is that the context of insurance and financial services makes fake support, policy, document, and payment messages more convincing.\u003C\u002Fp>\n\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Verified data types are email addresses, job titles, names, phone numbers, physical addresses, forms of address, and support requests. Support requests may not be present at the same level of detail in every record; however, they can give the impression that a customer has previously received service, document, or account support. This also makes it easier for fake agent messages to appear credible.\u003C\u002Fp>\n\u003Cp>Phone, physical address, and salutation information enable targeting through channels other than email. In the context of insurance, users may perceive messages about policy renewal, missing documents, premium payment, claims process, or account verification as genuine. Even if this data set does not contain financial account information, it carries a social engineering risk that exploits the customer trust relationship.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified event date is April 20, 2026, and the verified searchable scope is 237,810 unique email addresses. This number does not mean that all Canada Life customers were affected. The company's statement indicated that those affected may represent a small portion of the customer base. Additionally, the area for support requests may be present in some records; it should not be assumed that every individual has the same details.\u003C\u002Fp>\n\u003Cp>This record does not claim that passwords, social security numbers, insurance policy numbers, payment cards, bank accounts, credit information, medical files, or full financial account data were leaked. The verified scope is limited to contact, salutation, job title, and support request fields. The risk is misleading users with fake insurance and financial service messages rather than direct account takeover.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Individuals who have interacted with Canada Life in the context of customer service, insurance, retirement, group benefits, or financial services may be at risk. Records containing job titles and work context can help in preparing more personalized messages for corporate clients or employee benefits processes. Phone and address information increases the risk of fraud themed around fake calls and mail.\u003C\u002Fp>\n\u003Cp>Users who have opened a support request should also be careful. Attackers may act as if there is a real support process, asking to upload documents, make premium payments, renew policies, verify addresses, or update customer information. The presence of the correct greeting, name, phone number, or details similar to a previous support issue in the message does not prove that the request is real.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users in the matching area must ensure that they use a strong, unique password on their Canada Life account and associated email account. The password is not a verified data class in this incident; however, attempts may be made to collect passwords through fake login pages. Links in policy, document, payment, or support messages should not be used directly; the transaction should be initiated through the known official portal or customer service channel.\u003C\u002Fp>\n\u003Cp>Verification codes, payment information, social security numbers, additional identification documents, or account passwords should not be shared over phone calls. Requests that appear urgent, such as premium payments, missing documents, policy termination threats, or claims processes, should be verified through a secondary channel. Suspicious communications can be reported to the official support channel before being deleted.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Customer support data in insurance and financial services remains valuable for a long time even if it does not contain payment or password information. Users should use a unique password, two-factor authentication, and secure communication preferences for their insurance accounts. Old support requests and unused contact information should be reviewed regularly.\u003C\u002Fp>\n\u003Cp>From the perspective of institutions, the name, address, phone number, and salutation information in support requests can provide sufficient context for social engineering. Therefore, the retention period, access authorization, and notification templates of support records should be carefully managed. On the user side, it should be a basic habit to verify insurance and financial service messages through official channels, not share information over the phone, and confirm payment requests through a secondary channel.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The presence of a match with the email address in this record indicates that the address is included in a communication or support dataset associated with Canada Life. A match does not mean that the password, policy number, or financial account information has been leaked. The user should first determine which insurance, retirement, group benefit, or support process they used this email address for.\u003C\u002Fp>\n\u003Cp>The correct action is to secure the email account, verify insurance and support messages through official channels, be cautious with information requests received by phone, and confirm the authenticity of the request before sharing documents or payment information. This record should be handled with particular care, especially regarding insurance-related phishing and fake customer service messages.\u003C\u002Fp>","Canada Life Data Breach (237.8 Thousand Reported Records)","Canada Life Data Breach. 237.8 Thousand reported records are reported. Reported data: Email addresses, Job titles, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fcanadalife_com.webp",false,{"name":7,"sector":45,"country":46,"website":10,"websiteArchiveUrl":47,"websiteStatus":47,"websiteCheckedAt":13},"Insurance","Canada",""]