The LifeLabs data breach affected a significant number of users, exposing personal information that can be used for identity theft, phishing, and fraud. If you've ever had an account or relationship with LifeLabs, it's worth checking whether your data was involved.
What Happened
LifeLabs, the largest provider of medical laboratory testing in Canada, disclosed a cyberattack in December 2019 affecting approximately 15 million customers, primarily in Ontario and British Columbia. LifeLabs confirmed it paid a ransom to recover the stolen data, working with cybersecurity experts and law enforcement.
What Data Was Exposed
The breach exposed names, addresses, emails, login usernames and passwords, health card numbers, and — for a smaller subset of roughly 85,000 customers — actual lab test results.
Why This Still Matters
Even breaches from years ago remain a risk today. Stolen data is sold, traded, and reused indefinitely. Credentials from old breaches fuel credential stuffing attacks — automated attempts to reuse your email and password combination on other sites. If you reused a password anywhere, one old breach can compromise several current accounts.
How to Check If You Were Affected
Use our free breach checker below — enter your email and we'll scan it against known breach databases instantly, no signup required.
What to Do If You Were Affected
- Change any reused password immediately, starting with your most sensitive accounts.
- Enable two-factor authentication wherever it's offered.
- Monitor financial accounts closely if payment or banking data was involved.
- Watch for phishing — breach data is often used to craft convincing scam messages.
- Freeze your credit if your SSN or government ID number was exposed.
👉 Check your own exposure in 30 seconds → scan your email free.
Frequently Asked Questions
When did the LifeLabs data breach happen?
LifeLabs discovered the breach in October/November 2019 and publicly disclosed it on 17 December 2019, notifying approximately 15 million affected customers.
What data was stolen in the LifeLabs breach?
Names, addresses, emails, login credentials, and health card numbers were exposed for most affected customers. For approximately 85,000 customers, actual lab test results were also accessed.
Did LifeLabs pay the hackers?
Yes. LifeLabs confirmed it paid an undisclosed ransom to retrieve the stolen data, a decision that drew scrutiny from privacy regulators and cybersecurity experts.
How do I check if I was affected by the LifeLabs breach?
LifeLabs set up a dedicated customer support line and offered free identity theft and fraud protection insurance for one year. You can also check your email at Scan My Shadow.
What was the regulatory outcome of the LifeLabs breach?
Privacy commissioners in Ontario and British Columbia jointly investigated and found LifeLabs had inadequate security safeguards. A class-action settlement was later reached with affected customers.