Recent Major Hacks: Lessons for Small Businesses

Cybercrime isn't just a big business problem
img

In 2025, cybercrime has evolved from a backroom annoyance to a front-page threat. From hospitals to retailers, large-scale data breaches now dominate headlines. But beneath the media glare, a quieter crisis is unfolding: Canada's small businesses are under attack—and few are prepared.


The Myth: Only Big Targets Get Hit

When Canadians hear about cyberattacks, they often think of giants like Indigo, Sobeys, or LifeLabs. But nearly 1 in 4 cyber incidents in Canada last year involved businesses with fewer than 100 employees, according to the Canadian Centre for Cyber Security.

🛡️ Quick Fact: 60% of small businesses hit by a cyberattack in Canada go out of business within six months, often due to reputational damage and recovery costs.

Small firms are attractive to hackers precisely because they’re less protected. Limited budgets, fewer dedicated IT staff, and out-of-date systems make them low-hanging fruit for ransomware groups and phishing campaigns.

Case in Point: The Port of Québec Attack

In early 2025, a ransomware gang compromised systems linked to the Port of Québec’s logistics chain. While the primary breach affected a third-party contractor, multiple SMEs—including trucking companies and suppliers—were impacted. Operations halted, deliveries delayed, and some businesses lost critical weeks of revenue.

"We weren’t the direct target, but we paid the VHQjDbxaTb anyway."

Owner of a Montréal-based customs brokerage

This incident underscored a growing risk: supply chain exposure. Even if your systems are secure, your partners’ may not be.

Lessons from the Big Leaks

Several high-profile hacks in Canada over the past 24 months have revealed key patterns—and practical lessons—for small businesses:

  • Phishing is still king: The majority of breaches start with a single employee clicking a fake link or sharing credentials.
  • Cloud ≠ secure by default: Poorly configured cloud platforms were a vulnerability in at least 40% of breaches.
  • No backups, big problems: Companies without offsite or offline backups faced massive ransom demands or permanent data loss.
📌 Tip: Even basic measures like two-factor authentication (2FA), regular software updates, and mandatory employee training can reduce your breach risk by up to 80%.

Why Small Doesn’t Mean Safe

Small businesses are often victims of automated attacks—bots scanning the internet for exposed servers, unpatched WordPress sites, or misconfigured firewalls. These attacks don’t discriminate by company size.

In fact, many ransomware groups now operate as a service (“RaaS”), selling kits on the dark web that allow even low-level hackers to launch attacks for a few hundred dollars.

🕵️ Did You Know? The average cost of a ransomware attack on a Canadian small business in 2024 was $74,000—including downtime, legal fees, and forensic services.

The Role of Cyber Insurance

More Canadian SMEs are turning to cyber insurance for peace of mind—but coverage isn’t guaranteed. Insurers increasingly demand proof of cybersecurity practices: firewall audits, endpoint detection, and staff training certificates.

Failing to meet these requirements can void claims, leaving businesses stranded after an incident.

"Insurance doesn’t replace preparation. It only works if you’ve done your homework."

Cybersecurity consultant, Vancouver

Steps Every Small Business Should Take

You don’t need a CISO to stay protected. Here are foundational steps any small business in Canada can take today:

  • Implement 2FA on all platforms
  • Run regular phishing drills with staff
  • Update systems monthly and patch known vulnerabilities
  • Back up data offsite and test restores quarterly
  • Assign a cyber lead—even if it’s not a full-time role

Federal Support Is Growing—But Gaps Remain

Programs like the CyberSecure Canada certification offer tools and training for small firms. Grants are also available via provincial innovation agencies and chambers of commerce.

Still, many business owners say they feel overwhelmed. "I run a bakery, not a server farm," one Toronto owner joked. But the reality is, digital threats don’t care what you sell.

Never Miss a Breaking Story

Get instant notifications when major Canadian news breaks

The Bottom Line

In today’s economy, cybersecurity is as essential as locking your doors. For Canada’s small businesses, the stakes are high—but so are the opportunities to build resilience.


A single click can cost everything. But with the right tools and awareness, small businesses can punch above their weight when it comes to cyber defence.