Desjardins Group is one of the largest financial groups in America. It was founded in 1900, in the city of Levis, Canada.
Yesterday, June 20, the Group announced that a large amount of personal information belonging to approximately 2.9 million members of the Desjardins Group had been leaked . The leak was attributed to an employee who disclosed the information to individuals outside the organization without authorization.

The press release, which has been published, details the information that was leaked. These include: members' first and last names, date of birth, social security number, home address, phone number, email, and information related to banking activities and products.
Regarding the Group's business, the information that was leaked was the following: business name, business address, business phone number, owner name and usernames on the AccèsD Affaires account. The press release also stated that some personal information related to AccèsD Affaires accounts may have been exposed.
Desjardins Group was notified of the breach on June 14, 2019, by police Laval. Officers presented evidence that the personal information of 2.9 million members (2.7 million individuals and 173,000 businesses) had been disclosed to individuals outside the organization.
The interesting fact about this case is that the leak was not caused by an external attack . The person responsible is an employee of the Group. The Desjardins Group informed the Canadian Consumer Protection Agency, the Quebec Information Commission and the Autorité des marchés financiers about the incident and fired the employee.
Despite the massive data leak, the company assured customers that they were not at risk. Specifically, it stated:
“Desjardins Group was not the target of a cyberattack. Our computer systems have not been compromised in any way by this incident. We understand that this is a concerning situation. We sincerely apologize for the inconvenience. Your assets and accounts at Desjardins are protected. You will not suffer any financial loss if unauthorized transactions are made on your Desjardins accounts.”.
It also stated that members' passwords, PINs, and credit and debit card numbers have not been compromised.
This is the first time that Desjardins Group has been the victim of such an incident. The company pledged to do everything it can to prevent something like this from happening again, although as it said, no company is completely protected from attempts to steal personal information these days.
The Group said it would offer a free 12-month credit monitoring program for all members affected by the breach and suggested some ways to protect themselves.
