CPA Canada Data Breach: 2026 Update for Accountants

9 sources
Comments (0)

CPA Canada data breach in 2026: the short answer

The CPA Canada breach is an old incident, but its data can still be used. In June 2020 Chartered Professional Accountants of Canada said a cyberattack on its website let an unauthorized party reach personal information of over 329,000 members and other stakeholders.[7][8] Names, addresses, email addresses and employer names were involved, along with passwords and credit card numbers that the association said were protected by encryption.[7]

We found no newer breach of CPA Canada itself as of 2026. What did change is the focus on phishing. In 2026 CPA Canada and the Canada Revenue Agency published a three-part video series that teaches accountants to spot and respond to phishing.[9] This page is for CPA members, small accounting firms and their clients who want to know what the old leak means today.

CPA Canada data breach at a glance
QuestionAnswer
Who was hitChartered Professional Accountants of Canada and its website[7]
When it was disclosedJune 4, 2020[7]
People affectedOver 329,000 members and other stakeholders[7][8]
Data involvedNames, addresses, emails, employer names, encrypted passwords and card numbers[7]
Warning sign before itA phishing campaign aimed at members in April 2020[7][3]
Newer CPA Canada breach in 2026None found in the sources we read

Timeline: from the 2015 guide to the 2026 phishing series

Timeline of the CPA Canada data breach from the 2015 cybersecurity guide and the April 2020 phishing notice to the 2026 CPA Canada and CRA phishing series
Key dates around the CPA Canada data breach, 2015 to 2026. Sources: BleepingComputer, CPA Practice Advisor, CPA Canada.
Dated events around the CPA Canada breach
DateEvent
2015CPA Canada publishes Cyber-Security Opportunities for Smaller Accounting Firms[5]
April 24, 2020CPA Canada notifies members about a phishing campaign aimed at them[7][3]
June 4, 2020CPA Canada discloses that over 329,000 people were affected[7][2]
June 5, 2020CPA Practice Advisor reports the breach to the accounting trade[8]
2026CPA Canada and the CRA publish a three-part phishing protection series[9]

What changed since 2020

The breach did not lead to a public account of who was behind it in the sources we read. The association said it had told affected people directly and urged them not to answer emails that ask for sensitive data, links or attachments.[7] That warning still applies, because names, addresses and employer names do not expire the way a password does.

The bigger change is how openly the profession now treats phishing as a working risk. The 2026 series from CPA Canada and the Canada Revenue Agency covers warning signs, safe online habits, how to help clients avoid scams and what to do after an incident.[9] That is a step beyond the 2015 guide for small firms, which mostly framed security as a business opportunity.[5]

For searchers looking for cybersecurity for Canadian accountants, the lesson is simple. A breach at a professional body gives criminals a list of people who handle money and client data. That list stays useful for years, so the follow-up phishing matters more than the original leak.

Risks that follow a breach like this (our analysis)

We have not seen evidence that the 2020 data was used in a named campaign. The risks below are our analysis of how leaked member data is usually abused.

  • Fake CPA Canada notices. Emails that look like membership renewals, magazine updates or security alerts and ask you to log in through a link.
  • Fake IT department messages. The April 2020 campaign posed as the employer's IT team and pushed a password change.[7]
  • Tax season pretexts. Messages that pose as the CRA or a client and carry a malicious attachment, the threat the 2026 CPA Canada and CRA series addresses.[9]
  • Invoice and payment fraud. Leaked employer names help criminals write believable messages to a firm's finance staff.
  • Card fraud attempts. Card data was reported as encrypted, but you should still watch statements for unknown charges.[7]

Safe steps for CPA members and accounting firms

Six safe steps for CPA members and accounting firms after the CPA Canada data breach: new passwords, two-factor sign-in, link checks, card review, staff training, reporting
Six safe steps for CPA members and small accounting firms. 2-Spyware, 2026.

1. Change old passwords. If you used your CPA Canada password anywhere else before 2020, change it on every site where you reused it. Use a password manager to keep each one unique.

2. Turn on two-factor sign-in. Add a second step to email, accounting software and bank accounts. A leaked password alone then does not open the account.

3. Type the address yourself. Do not follow links in emails that ask you to change a CPA Canada password. Open the site from a bookmark, the step the association itself urged in 2020.[7]

4. Check card statements. Card numbers were stored encrypted, but review statements and ask your bank for a new card if you see anything odd.[7]

5. Train your staff. Share the 2026 CPA Canada and CRA phishing series with everyone who handles client files.[9] A short session before tax season covers the most common pretexts.

6. Report phishing. Report fake messages to the Canadian Anti-Fraud Centre and to the brand being copied. Our guide on how to report phishing shows the steps.

What is still unknown

  • Who carried out the 2020 attack. We found no public attribution in the sources we read.
  • Exactly when the intrusion started. The disclosure gave no start date.[7]
  • Whether the leaked data was later sold or reused. We found no report that ties it to a named campaign as of 2026.

Our original 2020 report

The text below is our report as first published in 2020. We keep it unchanged for the record; the sections above bring it up to date.

Chartered Professional Accountants of Canada[1], a.k.a. CPA Canada revealed a data breach[2] that affected nearly 330k members of the association. According to cybersecurity researchers, the attack has been initiated against the servers of the association, including the official website the cpacanada.ca.

Since the attack is currently under investigation, the company does not expatiate on the details. However, the CPA Canada President and CEO Joy Thomas said that hackers targeted the information regarding the distribution of the CPA Magazine, as well as names, email addresses, and home addresses of the members. Hackers obtained credit card numbers and passwords of 329,000 association members as well. However, CPA Canadian assured that banking information and passwords have been protected by encryption.

A scam campaign initiated back in April might have been a warning from hackers

Back in April 2020, CPA Canada released an official security notice for its members[3]. According to the association, the inboxes of the association members' emails have been actively spammed with phishing emails that urged the members to change passwords due to the security breach initiated against the cpacanada.ca website.

We are told that these emails appear to originate from the IT department of the employer of the individual receiving the message. These emails suggest that their IT department suspects a cybersecurity compromise with the cpacanada.ca domain.

Based on the gathered information, the IT department of the association suspected the possible data breach, though it hasn't been confirmed. However, members have been urged to ignore the phishing emails, especially if they contain hyperlinks to the website of the association where the "Change password" section is disclosed. This domain may be hacked, thus the provided login details can leak to hacker's hands directly.

Although the exact date of the current CPA Canada security breach is not disclosed yet, it's very likely that the targeted attack has begun in April and manifested in early June. Upon revelation, the association contracted the Canadian Anti-Fraud Centre[4] and started working with the law enforcement agencies. All affected individuals have been personally informed about the breach.

Safeguarding the information in our care is one of our most important responsibilities and we sincerely regret any concern this incident may cause.

CPA Canada – is one of the largest national accounting organizations is a huge interest for hackers

Chartered Professional Accountants of Canada (CPA) is a big fish for hackers. The association is one of the largest national accounting organizations all across the world. It unifies the Society of Management Accountants of Canada (CMA Canada), the Canadian Institute of Chartered Accountants (CICA), and the Certified General Accountants of Canada (CGA-Canada) accounting organizations.

CPA's members are known as the most professional business experts supporting the organizations in Canada, the U.S, Europe, and other continents. It has over 210,000 professional accountants that have acquired valuable experience and data throughout the year of the membership.

Organizations like CPA Canada is always at a heightened security risk since hackers target big companies that contain valuable data in the servers. This fact is acknowledged by the association itself. Thus, in 2015 it has released an official document called Cyber-Security Opportunities for Smaller Accounting Firms[5].

Canadian accounting professionals are right to be concerned about IT security because emerging threats are significant and the risk of falling prey to malicious attacks is growing. A security incident can impact organizations on many levels, including time, money, reputation, and their professional status as members of CPA Canada. A data breach raises the likelihood of losing more than just business data. Even more crucially, client data may be lost as well.

According to CPA Canada's research, a total of 43% of survey respondents have already experienced cyber-attacks that impacted the business significantly. The association is taking measures to protect its members, their data, and reputation. However, hackers create novel methods[6] to attack suchlike companies, organizations, and associations, thus extra security measures should be taken to ensure protection.

Frequently asked questions

What happened in the CPA Canada data breach?

A cyberattack on the CPA Canada website let an unauthorized party reach personal information of over 329,000 members and other stakeholders, disclosed on June 4, 2020.{7} The data included names, addresses, email addresses and employer names, plus passwords and card numbers the association said were encrypted.{7}

Is CPA Canada safe to use in 2026?

We found no newer breach of CPA Canada as of 2026. The main risk today is phishing that copies the association. Open cpacanada.ca yourself instead of following email links, and use a unique password with two-factor sign-in where it is offered.

What cybersecurity help exists for Canadian accountants?

CPA Canada and the Canada Revenue Agency publish a three-part video series on phishing protection for CPAs.{9} It covers warning signs, safe online habits, helping clients avoid scams and what to do after an incident. CPA Canada also published a cybersecurity guide for smaller firms in 2015.{5}

Were passwords and credit cards stolen in the CPA Canada breach?

They were reached, but CPA Canada said passwords and credit card numbers were protected by encryption.{7} That lowers the risk, but it does not remove it. Change any password you reused elsewhere and check card statements for unknown charges.

Was the CPA Canada breach linked to phishing?

Yes, a phishing campaign aimed at CPA Canada members came first. The association warned about it on April 24, 2020, weeks before it disclosed the breach.{7} The fake emails posed as the recipient's IT department and asked for a password change.{7}

How can I check whether my data leaked?

Use a leak checker to see whether your email appears in known breaches. Our [leak check](/check) searches public breach data. If your address shows up, change the password on that site and on every site where you used the same password.

Comments (0)

What do you think?

0 comments

No comments yet. Be the first.

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year