Canadian Cyber Security Journal
SOCIAL:
Filed under: Featured, News

Interlock Ransomware Hits Centre for Newcomers: 380 GB of Immigrant Client Data Stolen — What Canadian Nonprofits Must Do Now

What Happened

The Interlock ransomware group claimed a cyberattack against Centre for Newcomers, a Calgary-based nonprofit organization providing immigration, settlement, and integration services to newcomers across Alberta. The group published the organization on its dark web leak site on July 17, 2026, claiming responsibility for stealing 380 GB of data. The breach came to light on July 20. The stolen data reportedly includes personal client records, company financial information, current organizational reporting, and HR planning documents. No ransom payment or data recovery status has been publicly disclosed by the organization.

Why This Matters for Canadian Organizations

This breach strikes at one of the most sensitive intersections in the Canadian nonprofit sector: the protection of personal data belonging to immigrants, refugees, and newcomers who depend on these organizations for critical services. Clients of Centre for Newcomers likely shared immigration status documents, identification details, financial records, and other sensitive personal information as part of their service intake. This data, in the hands of a ransomware extortion group, creates direct risks of identity fraud and targeted exploitation for a population already working through complex legal and bureaucratic processes.

The attack also demonstrates Interlock’s continued focus on mid-size Canadian organizations providing public services. Prior Interlock victims in Canada include healthcare and public-sector entities. Nonprofits often operate with limited IT budgets, minimal dedicated security staff, and legacy infrastructure — making them attractive targets relative to their data sensitivity. Under PIPEDA, Centre for Newcomers has obligations to notify affected individuals and the Office of the Privacy Commissioner if the breach poses a real risk of significant harm. Given the nature of the data involved, notification is almost certain to be required.

Canadian nonprofits receiving government funding for settlement services should treat this attack as a sector-wide alert. Interlock has demonstrated the willingness to target organizations regardless of their charitable mandate or the vulnerability of those they serve.

What to Do

Organizations in the settlement and nonprofit sector should immediately assess their exposure by auditing what client data they hold, where it is stored, and who has access. Key steps include reviewing backup integrity and offline backup availability, confirming endpoint detection and response (EDR) coverage across all systems, and verifying multi-factor authentication on all remote access and email accounts. Organizations should also review their incident response plans and confirm contact information for legal counsel and a breach notification process under PIPEDA. If you operate in Alberta, PIPA obligations apply alongside federal requirements. Engaging a managed security service provider for a security posture review is advisable for nonprofits without dedicated security resources.

Enjoy this article? Don’t forget to share.