The Desjardins data breach affected a significant number of users, exposing personal information that can be used for identity theft, phishing, and fraud. If you've ever had an account or relationship with Desjardins, it's worth checking whether your data was involved.

What Happened

Between 2018 and June 2019, an employee at Desjardins, Canada's largest credit union, used their internal access to extract member data and share it with third parties without authorization. Desjardins first disclosed the incident in June 2019, initially estimating 2.9 million affected members, but later revised the number to nearly all 9.7 million members and some business clients after further investigation.

What Data Was Exposed

The exposed data included names, addresses, birth dates, Social Insurance Numbers (SIN), email addresses, phone numbers, and details about account transaction habits. SINs are Canada's equivalent of a Social Security number and are highly valuable for identity theft.

Why This Still Matters

Even breaches from years ago remain a risk today. Stolen data is sold, traded, and reused indefinitely. Credentials from old breaches fuel credential stuffing attacks — automated attempts to reuse your email and password combination on other sites. If you reused a password anywhere, one old breach can compromise several current accounts.

How to Check If You Were Affected

Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.

What to Do If You Were Affected

👉 Check your own exposure in 30 seconds → scan your email free.

Frequently Asked Questions

When did the Desjardins data breach happen?

The unauthorized data extraction occurred between 2018 and June 2019 by a Desjardins employee. It was publicly disclosed on 20 June 2019, with the scope revised upward in the months that followed.

What data was stolen in the Desjardins breach?

Names, addresses, birth dates, Social Insurance Numbers (SIN), email addresses, phone numbers, and account transaction habit data for nearly all of Desjardins' 9.7 million members were exposed.

How did the Desjardins breach happen?

A Desjardins employee with internal database access extracted member data over a period of months and shared it with people outside the organization, reportedly for financial gain. This makes it an insider breach rather than an external hack.

How do I check if I was affected by the Desjardins breach?

Given the scope (nearly all members), Desjardins offered free credit monitoring to affected members. You can also check your email at Scan My Shadow and monitor your credit report through Equifax or TransUnion Canada.

What did Desjardins do after the breach?

Desjardins offered free Equifax credit monitoring to all members for life, reimbursed any resulting fraud losses, and faced a class-action lawsuit that resulted in a settlement.

Sources

Related Reading