Introduction
On June 14, 2019, the Laval police force informed the Desjardins Group “that the personal information of more than 2.9 million members had been shared with individuals outside the organization.” Desjardins agreed to pay “nearly $201 million to settle a class-action lawsuit related to” this data breach. The Office of the Privacy Commissioner of Canada (OPC) recorded that the data breach “affected close to 9.7 million individuals in Canada and abroad.” The police arrested eight individuals connected to this incident, one being a Desjardins employee who allegedly leaked the stolen data to external sources. As of October 20, 2025, according to La Presse, the data remains at large on the Dark Web.
This paper argues that despite Desjardins’ extensive cybersecurity policies, its failure to enforce them allowed a malicious employee to exploit the weaknesses those policies were designed to eliminate. Rather than backing its rules with technical controls, active monitoring, and effective training, Desjardins relied on employees to comply voluntarily. Its failure to enforce its retention policies then magnified the breach, exposing millions of files it should no longer have held. Finally, this paper recommends that Desjardins turn its cybersecurity policies into mandatory, technically enforced controls to limit the possibility of a similar breach and proposes offering regulatory bodies binding authority.
To make this argument, this paper first explains how Desjardins stored personal information and how the malicious employee exploited that system. It then argues that the breach resulted from gaps between Desjardins’ policies and its practices, and that its failure to implement its retention policies magnified the breach. Finally, it considers whether the insider threat was preventable and offers recommendations.
What Happened
Desjardins collected personal information (including “first and last names, dates of birth, social insurance numbers, residential addresses, telephone numbers, email addresses and transaction histories”) from members and clients who bought or received its products. Desjardins stored this information in a “credit data warehouse” and a “banking data warehouse.” Access to the banking data warehouse “was segmented according to whether the information was confidential … or non-confidential,” but the credit data warehouse was not segmented and any employee could access all of the data, including personal data, if they had the proper authorization. Desjardins’ policy was to restrict “access to the personal information stored in the two data warehouses through specific access rights.” In practice, the policy failed.
The OPC found that marketing employees with authorized access copied personal information from both warehouses into a shared directory open to their entire department. Although Desjardins implemented a technological restriction to ensure that only authorized employees could access these data warehouses, it did not prevent authorized individuals from downloading “files containing personal information from the two data warehouses to shared drives accessible” to other marketing employees. It did not force authorized users to place these files in the confidential shared directory, restricted to those with proper authorization.
Thus, every month between January 2016 and June 2018, employees from the marketing department “used a manual script” to transfer the compromised data from the credit warehouse to folders in “the shared directory.” And on September 18, 2017, and November 13, 2018, other employees from the marketing department copied personal data from the banking warehouse into the shared directory instead of the department’s confidential shared directory. All of these actions contravened the bank’s policy of best practices to protect confidential data. However, Sébastien Boulanger-Dorval, the malicious employee identified as the source of the breach and whom police later charged, did not have authorization to access the confidential information; he downloaded it into his user folder and another shared folder. Then, using a file sharing software, he compiled that information onto his work computer; he then copied it onto a USB key and leaked the data.
Police have since arrested eight individuals. Two culprits, Ayoub Kourdal and Imad Jbara, are now in jail. Boulanger-Dorval awaits his criminal proceedings, as do the remaining accused. Beyond the settlement, Desjardins provided members “Equifax credit monitoring service coverage for five years.” Desjardins also agreed to external auditing and compliance reporting.
Why It Happened
Desjardins’ data breach occurred because Desjardins did not enforce its cybersecurity policies. First, it did not enforce its access controls or adequately train its employees; second, it did not adequately monitor employee activity; third, it lacked technological safeguards against data leaving its systems; and fourth, it did not have an implemented data retention policy, which magnified the breach’s scope. Ultimately, these cybersecurity failures reveal a gap between what Desjardins’ policies were and what the bank actually did to protect personal data. Quebec’s Commission d’accès à l’information (CAI) reached a similar conclusion, finding that Desjardins violated sections 10, 12, and 20 of Quebec’s private-sector privacy law.
Poor Access Controls and Employee Training
Desjardins’ data breach partially occurred because the bank neither enforced its data protection policies nor ensured that its employees understood them. Desjardins had a policy called the Standard de sécurité sur la protection des données. The standard required confidential information to be protected throughout its life cycle and access to it to be controlled. The Standard de sécurité sur l’utilisation de données confidentielles ou secrètes hors des environnements de production required confidential data to be masked, and each transfer of it to be authorized, before it left the protected production environment. Yet Desjardins had no safeguards stopping confidential information from moving to open folders. And employees could move it out of protected zones unmasked, without receiving authorization.
Certain marketing employees exploited this gap, whether knowingly violating company policy or not. Indeed, Desjardins offered cybersecurity training, though it seems these employees either did not understand the importance of protecting confidential data or chose to ignore it; because rather than using the department’s restricted folders, they uploaded confidential information into shared drives, open to all employees in their department. These actions constituted “non-compliant processing according to Desjardins’ policies and procedures, and did not follow best practices.”
Accordingly, Desjardins failed to follow the Personal Information Protection and Electronic Documents Act (PIPEDA) principles 4.7.3(b) and (c), which call for “organizational measures, for example, security clearances and limiting access on a ‘need-to-know’ basis” and “technological measures, for example, the use of passwords and encryption” when handling confidential personal data. It also failed to uphold principle 4.7.4, which states that “organizations shall make their employees aware of the importance of maintaining the confidentiality of personal information.”
The employees’ ability to move confidential information into shared files reveals that Desjardins had poor information access controls and that Desjardins inadequately trained its employees regarding data breach prevention. By exploiting this environment, the malicious employee was able to access and download data he was never authorized to see.
Passive Monitoring/Lack of Oversight
Desjardins’ lack of oversight further contributed to the breach. Its security standards required logging security events, an alert system based on event monitoring, and monitoring to find confidential data in unauthorized repositories. As with its data transfer policies, however, Desjardins failed to implement these requirements. Its data loss prevention (DLP) solution was only partially deployed, it had no user and entity behaviour analytics (UEBA) tool to flag abnormal downloads, and it was “limiting itself to passive measures such as analyzing event logs only after incidents were reported.”
More importantly, Desjardins knew the risk. Before the breach was detected, its internal risk analysis identified USB keys as a high data loss risk and recommended monitoring for exfiltration. Desjardins did not fully implement the report’s recommendations, and the employee extracted the data by USB – “precisely one of the scenarios envisioned in Desjardins’ report.” This suggests that Desjardins failed to uphold PIPEDA principle 4.7.3(c), which requires “technological measures” to protect personal information.
This passive monitoring and these ignored warnings, combined with poor access controls and unaware employees, fostered a weak cybersecurity environment at Desjardins. It let the malicious employee exfiltrate personal information undetected for at least 26 months, until the Laval police discovered it. The breach occurred not because the risk was unforeseeable, but because Desjardins identified it and did not act.
Technological Safeguards
Desjardins’ poor technological safeguards regarding confidential client and customer information further aided the data breach. Its policy, Standard Mouvement sur l’utilisation des technologies, banned storing personal information on outside devices, but its technological systems did not block personal USB drives. Desjardins knew of this technological issue, but it did not fix it quickly enough to prevent the breach.
Combined with the bank’s passive oversight, poor policy enforcement, and unaware employees, this gap amplified the cybersecurity risk; it let the malicious employee copy the data to a USB key and leak it.
Unimplemented Data Retention Policy
Desjardins’ failure to enforce its own retention policies also exacerbated the extent of the data breach. Desjardins had a directive, the Directive Mouvement sur la gestion des documents, and a policy, the Politique sur la protection des renseignements personnels. Both required personal information to be kept only as long as necessary to fulfill the purposes for which it was collected. Yet Desjardins never finalized a document retention schedule and had no procedures for destroying personal information at the end of its life cycle. Seven months after the incident, it still could not determine how long the compromised inactive accounts should have been kept.
In effect, the bank failed to follow PIPEDA principle 4.5.3. It provides that personal information “that is no longer required to fulfil the identified purposes should be destroyed, erased, or made anonymous,” and that organizations “shall develop guidelines and implement procedures to govern the destruction of personal information.”
Desjardins’ unimplemented retention policies and inability to adhere to PIPEDA principle 4.5.3 exacerbated the potential consequences of its cybersecurity weaknesses. By not implementing its data retention policy, the bank created the possibility for massive quantities of unnecessary personal data to be leaked if there were ever a cybersecurity breach. Its failure to destroy this data, combined with its poorly trained employees, lack of oversight and technological safeguards, ultimately created the environment for the data to be leaked.
Preventable?
Despite these cybersecurity weaknesses, one could argue that insider threats are impossible to prevent. The malicious employee passed a security check and signed annual code-of-conduct attestations and a confidentiality agreement, and the OPC found Desjardins’ screening practices acceptable.
This argument, however, misunderstands the purpose of enforcement. Enforced controls do not predict who will act maliciously. They limit what a malicious employee can access and how long they can go undetected. Here, the employee extracted data for at least 26 months. Moreover, the breach was foreseeable: Desjardins’ own risk analysis identified USB keys as a high risk, yet USB blocking had not been activated for the marketing team. It ultimately allowed the malicious employee to exfiltrate the data. Because no screening process can guarantee an employee’s loyalty, Desjardins could not rely on trust alone. It required greater oversight, training, technological safeguards, policy enforcement, and clear data retention policies to prevent a data breach from happening.
Recommendations
Desjardins’ data breach stemmed from its failure to enforce its own cybersecurity policies. Desjardins should therefore make its existing rules mandatory and technically enforced. Since the breach, Desjardins has blocked removable storage devices across all business lines and adopted active monitoring of employee activity. Furthermore, the OPC recommended, and the CAI ordered, progress reports every six months and an independent external audit. Desjardins should build on these measures in the following four ways. Additionally, this paper proposes passing Bill C-36 or affording the OPC’s findings binding authority.
1. Access Controls Through Technology
First, Desjardins should enforce access controls through technology. Its systems allowed authorized users to move confidential data wherever they wished. Desjardins should apply the principle of least privilege, mask confidential data before it leaves protected environments, and regularly attest to employees’ access, as the Office of the Superintendent of Financial Institutions’ (OSFI) Guideline B-13 expects. It should also block USB devices and deploy DLP controls “for data at rest, data in transit and data in use.” Doing so will enhance its cybersecurity because employees cannot simply ignore technical controls, but are forced to abide by them.
2. Active Monitoring
In addition, Desjardins should actively monitor employee activity. The U.S. National Institute of Standards and Technology (NIST) calls for personnel activity to be “monitored to detect potential cybersecurity events,” and OSFI expects institutions to detect “user and entity behaviour anomalies.” Desjardins should also track security-review recommendations until they are implemented. Active monitoring would enhance cybersecurity because it catches misconduct as it happens. Indeed, had Desjardins flagged the employee’s abnormal downloads, it could have stopped the breach before 26 months passed.
3. Culture of Vigilance
Desjardins should also test its training and build a culture of vigilance. Desjardins could not show that its employees understood its training, so it should “regularly test” their awareness, as OSFI recommends. Culture matters: NIST warns that a risk management strategy inconsistent with an organization’s culture will be “difficult if not impossible to implement.” Following the International Civil Aviation Organization’s (ICAO) approach to safety, Desjardins should treat cybersecurity as “everybody’s responsibility.” Creating a culture of vigilance will make every employee check on misconduct. Continuous testing would show whether employees truly understand data policies and what more is needed to build that culture.
4. Data Retention Schedule
Fourth, Desjardins should finalize its retention schedule and automatically destroy or anonymize expired data, as the OPC recommended and PIPEDA principle 4.5.3 requires. By implementing automation, Desjardins will enhance cybersecurity because it will not rely on employees remembering to delete files, and data that no longer exists will not be stolen. Destroying expired data would have protected 3.9 million inactive Desjardins files.
5. Binding Authority
Finally, voluntary compliance is insufficient. Under PIPEDA, the OPC can only make recommendations, whereas the Commission d’accès à l’information du Québec can issue binding orders. Jacqueline Eggenschwiler argues that hierarchical, law-based governance is best suited to crises. Arianna Vettorel warns that voluntary regimes risk producing fragmented rules. Canada’s National Cyber Security Strategy already commits the federal government to “explore legislation, regulation, and incentives.” Bill C-36, introduced in June 2026, would grant binding powers, though to a new Digital Safety and Data Protection Commission rather than the OPC. Parliament should therefore pass Bill C-36 or give the OPC the power to issue binding orders and impose penalties. A binding authority would work best because it would give institutions like Desjardins a legal requirement to fix weaknesses rather than relying on their goodwill.
Conclusion
Desjardins’ 2019 data breach occurred because it failed to enforce its cybersecurity policies. Its rules prohibited moving confidential data into open folders, storing personal information on outside devices, and keeping data longer than necessary. Yet its systems permitted all three. By relying on employee trust rather than technical controls, active monitoring, and tested training, Desjardins created an environment that allowed a single employee to exfiltrate the personal information of nearly 9.7 million people over at least 26 months. Its failure to destroy unneeded data magnified the harm. Years later, that data still circulates online. The breach offers a lasting lesson for every institution holding personal information: a policy is nothing without enforcement.
Bibliography
Legislation
Act respecting the protection of personal information in the private sector, CQLR c P-39.1.
Personal Information Protection and Electronic Documents Act, SC 2000, c 5.
Prospective Bill
Bill C-36, An Act to enact the Protecting Privacy and Consumer Data Act, to amend the Personal Information Protection and Electronic Documents Act and to make amendments to other Acts, 1st Sess, 45th Parl, 2026.
Major Policy Works
Commission d’accès à l’information du Québec. Fédération des caisses Desjardins du Québec. Decision no. 1020846-S. December 11, 2020.
International Civil Aviation Organization. Aviation Cybersecurity Strategy. Montréal: International Civil Aviation Organization, October 2019. https://www.icao.int/cybersecurity/Pages/Cybersecurity-Strategy.aspx.
Joint Task Force Transformation Initiative. Managing Information Security Risk: Organization, Mission, and Information System View. NIST Special Publication 800-39. Gaithersburg, MD: National Institute of Standards and Technology, March 2011. https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-39.pdf.
National Institute of Standards and Technology. Framework for Improving Critical Infrastructure Cybersecurity. Version 1.1. Gaithersburg, MD: National Institute of Standards and Technology, April 16, 2018.
Office of the Privacy Commissioner of Canada. Investigation into Desjardins’ Compliance with PIPEDA Following a Breach of Personal Information between 2017 and 2019. PIPEDA Findings #2020-005. Ottawa: Office of the Privacy Commissioner of Canada, December 14, 2020. https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2020/pipeda-2020-005/.
Office of the Superintendent of Financial Institutions. Technology and Cyber Risk Management. Guideline B-13. Ottawa: Office of the Superintendent of Financial Institutions, July 31, 2022. https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/technology-cyber-risk-management.
Public Safety Canada. Canada’s National Cyber Security Strategy: Securing Canada’s Digital Future. Ottawa: Public Safety Canada, 2025. https://www.publicsafety.gc.ca/cnt/rsrcs/pblctns/ntnl-cbr-scrt-strtg-2025/ntnl-cbr-scrt-strtg-2025-en.pdf.
Academic Articles
Eggenschwiler, Jacqueline. “A Typology of Cybersecurity Governance Models.” St Antony’s International Review 13, no. 2 (2018): 64–78.
Vettorel, Arianna. “Cybersecurity in New Space and the Problem of International Regulation.” Air and Space Law 49, no. 3 (2024): 311–26.
News Articles
Biron, Pierre-Paul. “Vol de données chez Desjardins: Sébastien Boulanger-Dorval et Jean-Loup Masse-Leullier remis en liberté.” Le Journal de Québec, July 8, 2024. https://www.journaldequebec.com/2024/07/08/vol-de-donnees-chez-desjardins-sebastien-boulanger-dorval-et-jean-loup-masse-leullier-remis-en-liberte.
Canadian Press. “Desjardins Data Breach: Laval Police Arrest 3 Suspects, Fourth One Being Sought.” CTV News, June 12, 2024. https://www.ctvnews.ca/montreal/article/desjardins-data-breach-laval-police-arrest-3-suspects-fourth-one-being-sought/
Canadian Press. “Desjardins Settles 2019 Data Breach Class-Action Lawsuit for Up to Nearly $201 Million.” RCI, December 16, 2021. https://ici.radio-canada.ca/rci/en/news/1848138/desjardins-settles-2019-data-breach-class-action-lawsuit-for-up-to-nearly-201m.
Cauchy-Vaillantcourt, Mark. “Les données d’un million de Québécois refont surface sur le dark web.” La Presse, October 20, 2025. https://www.lapresse.ca/actualites/justice-et-faits-divers/2025-10-20/fuite-de-renseignements-chez-desjardins/les-donnees-d-un-million-de-quebecois-refont-surface-sur-le-dark-web.php.
CBC News. “5 More Arrests, Including Primary Suspect, in Connection with Desjardins Data Leak.” June 13, 2024. https://www.cbc.ca/news/canada/montreal/desjardins-data-leak-boulanger-dorval-charges-1.7233805.
Cherry, Paul. “Men Who Defrauded Desjardins Clients out of Millions Sentenced to Prison Terms.” Montreal Gazette, January 20, 2026. https://montrealgazette.com/news/local-crime/desjardins-clients-theft-sentencing/.
O’Kane, Josh. “Desjardins Knew It Had Vulnerabilities before Massive 2019 Data Breach, Privacy Watchdog Says.” Globe and Mail, December 14, 2020. https://www.theglobeandmail.com/business/article-desjardins-knew-it-had-vulnerabilities-before-massive-2019-data-breach/.
Rukavina, Steve. “SQ Questions 17 People Who May Have Tried to Acquire Leaked Desjardins Data.” CBC News, September 19, 2019. https://www.cbc.ca/news/canada/montreal/sq-investigates-desjardins-data-breach-1.5289595.
Websites
Canadian Press. “Five More Arrests, Including Main Suspect, in Fraud, Data Theft at Desjardins.” BC Freedom of Information and Privacy Association. June 13, 2024. https://fipa.bc.ca/five-more-arrests-including-main-suspect-in-fraud-data-theft-at-desjardins/.
Desjardins Group. “Desjardins Statement Concerning Unauthorized Access to Some Member Information.” Press release, PR Newswire, June 20, 2019. https://www.newswire.ca/news-releases/desjardins-statement-concerning-unauthorized-access-to-some-member-information-806079260.html.
Ferguson, Christopher, and Dongwoo Kim. “Bill C-36: A Third Attempt at Federal Private-Sector Privacy Reform.” Fasken, June 18, 2026. https://www.fasken.com/en/knowledge/2026/06/bill-c-36.
Mon Technicien. “Desjardins Leak 2025: The Return of Data Exposes Vulnerabilities That Remain Unresolved.” November 6, 2025. https://www.montechnicien.com/en/desjardins-leak-2025-the-return-of-data-exposes-vulnerabilities-that-remain-unresolved/.

Leave a Reply