Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Desjardins

Desjardins Vendor Cyber Rating & Cyber Score

desjardins.com

Desjardins Group is the largest cooperative financial group in North America and the fifth largest cooperative financial group in the world, with assets of $435.8 billion as at March 31, 2024. It was named one of Canada's Best Employers by Forbes magazine and by Mediacorp. To meet the diverse needs of its members and clients, Desjardins offers a full range of products and services to individuals and businesses through its extensive distribution network, online platforms and subsidiaries across Canada. Ranked among the world's strongest banks according to The Banker magazine, Desjardins has some of the highest capital ratios and credit ratings in the industry and the first according to Bloomberg News.


Desjardins A.I CyberSecurity Scoring

Desjardins
Company Information
Website:http://www.desjardins.com/fr/bienvenue.jsp
Employees number:44,288
Number of followers:390,459
NAICS:52211
Industry Type:Banking
Homepage:desjardins.com
Desjardins Risk Score (AI oriented)
Between 0 and 549
logo
DesjardinsBanking
Updated:
17/07/2026
483/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Desjardins Global Score (TPRM)
xxxx
logo
DesjardinsBanking
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Desjardins
DesjardinsCritical
Current Score
483C (CRITICAL)
01000
7 incidents
-62 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
486Before Incident
JULY 2026
559Before Incident
Breach
16 Jul 2026Desjardins
Desjardins: Final suspect in Desjardins data theft arrested in Mexico

Desjardins Data Breach

483After Incident
CRITICAL-76
DES1784220391
Final Suspect in Desjardins Data Breach Arrested in Mexico Maxime Paquette, the last remaining suspect in the Desjardins data breach investigation, was arrested in Cancun, Mexico, on July 16. The 40-year-old had been wanted by Quebec’s Sûreté du Québec (SQ) since June 2024 as part of Project Portier and Project D, which probed the theft and resale of personal data belonging to 9.7 million Desjardins members a breach first disclosed in 2019 that impacted nearly seven million Quebecers. Paquette’s arrest marks the conclusion of the SQ’s hunt for all identified suspects in the case. Another fugitive, Juan Pablo Serrano, was detained in Spain in January 2026 and remains in custody pending extradition. Paquette faces charges in Canada, including fraud over $5,000, identity theft, and trafficking in identifying information. Authorities allege he used stolen Desjardins data between March 2018 and September 2020 to execute fraud schemes and sold compromised personal information on the dark web. The SQ has previously warned that the exposed data remains unsecured. The breach, one of Canada’s largest, involved the unauthorized access and distribution of sensitive client information, with ongoing risks of financial fraud. Paquette will remain in Mexican custody while extradition proceedings move forward.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial Gain
IMPACT
Data Compromised: Personal and sensitive client informationBrand Reputation Impact: SignificantLegal Liabilities: YesIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Personal and sensitive client informationNumber Of Records Exposed: 9.7 millionSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
JUNE 2026
555Before Incident
MAY 2026
550Before Incident
APRIL 2026
547Before Incident
MARCH 2026
540Before Incident
FEBRUARY 2026
588Before Incident
Breach
08 Feb 2026Desjardins
Desjardins Group, Dolby Laboratories and SK Telecom: CoinbaseCartel hacker claims American audio behemoth Dolby

CoinbaseCartel Claims Data Breach of Dolby Laboratories in Latest Extortion Scheme

534After Incident
CRITICAL-54
DESSK-DOL1770631353
CoinbaseCartel Claims Data Breach of Dolby Laboratories in Latest Extortion Scheme A newly emerged cybercriminal group, CoinbaseCartel, has added Dolby Laboratories to its dark web leak site, alleging a data breach over Super Bowl weekend (February 2026). The U.S.-based audio technology giant, which reported over $1.3 billion in revenue in 2025 and employs 2,000+ staff, joins a growing list of high-profile victims, including SK Telecom (South Korea’s largest mobile carrier) and Desjardins Group (Canada’s largest financial services cooperative). Despite denying ransomware operations, CoinbaseCartel’s tactics password-protecting stolen data and extorting victims via a dark web blog align with traditional ransomware cartels. The group, first observed in September 2025, previously targeted SK Telecom, threatening to leak source code after the company refused negotiations. Researchers note that some victims listed by CoinbaseCartel overlap with those claimed by other ransomware gangs, suggesting possible data recycling. Unlike typical ransomware groups, CoinbaseCartel restricts access to stolen data, likely to showcase it exclusively to potential buyers either the victim or other cybercriminals. No samples have been released to verify the breach’s severity. The group’s emergence follows a broader trend of law enforcement crackdowns, including the FBI’s seizure of the RAMP dark web forum, which has fueled distrust among cybercriminals. Dolby Laboratories has not yet responded to requests for comment. The incident underscores the persistent threat of double extortion tactics, where attackers both encrypt data and threaten to leak it unless demands are met.
INCIDENT DETAILS -
TYPE
Data Breach / Extortion
MOTIVATION
Extortion / Financial Gain
JANUARY 2026
583Before Incident
DECEMBER 2025
647Before Incident
Breach
25 Dec 2025Desjardins
Desjardins: Montana Attorney General launches investigation into Lee Enterprises data breach

Lee Enterprises Ransomware Attack and Data Breach

582After Incident
CRITICAL-65
DES1767941129
Montana AG Investigates Lee Enterprises Ransomware Attack Impacting 40,000 A ransomware attack on Lee Enterprises, a Davenport, Iowa-based media company, has prompted an investigation by Montana Attorney General Austin Knudsen. The breach, attributed to the Qilin ransomware group, compromised the personal data of nearly 40,000 employees and subscribers earlier this year. Lee Enterprises owns multiple newspapers in Montana, including the Helena Independent Record, Billings Gazette, Missoulian, and Montana Standard, as well as dozens of other publications nationwide. While the company has not publicly detailed the extent of the exposed data, the incident marks a significant cybersecurity failure for the media organization. The Montana AG’s office confirmed the investigation on Friday, though official details had not yet been posted on its website at the time of reporting. This follows a broader trend of escalating ransomware attacks, with 2023 seeing record-high incidents and payments, according to a FinCEN report. The breach adds to a growing list of cyber incidents in 2024, including a second data exposure in seven months at Methodist Homes of Alabama and Northwest Florida and a security lapse at Virginia Urology, where purported patient data began leaking online. Meanwhile, federal authorities secured a conviction against a Nigerian national for wire fraud, aggravated identity theft, and unauthorized computer access, underscoring the global reach of cybercrime. Lee Enterprises has not yet issued a public statement on the investigation’s status or remediation efforts.
INCIDENT DETAILS -
TYPE
Ransomware, Data Breach
IMPACT
Data Compromised: Personal data of nearly 40,000 employees and subscribersIdentity Theft Risk: Aggravated identity theft risk (referenced in related case)
DATA BREACH
Type Of Data Compromised: Personal dataNumber Of Records Exposed: Nearly 40,000Sensitivity Of Data: High (personally identifiable information)Personally Identifiable Information: Yes
NOVEMBER 2025
696Before Incident
Breach
06 Nov 2025Desjardins
Desjardins: Man wanted in connection to Desjardins data breach arrested in Spain

Desjardins Data Breach and Fraud Scheme

643After Incident
CRITICAL-53
DES1767719603
Key Suspect in Desjardins Data Breach Arrested in Spain After 17-Month Manhunt Juan Pablo Serrano, a fugitive wanted in connection with the 2024 Desjardins data breach, was arrested in Spain on November 6, 2025, following a joint operation by Spanish authorities, Quebec provincial police, and Interpol. Serrano, 40, had been at large since June 2024 and was among Quebec’s most wanted individuals. Interpol issued a Red Notice for his arrest, enabling global law enforcement to track and detain him. He now faces extradition to Canada, where he will be charged with identity theft, fraud exceeding $5,000, and trafficking in identity information. Serrano is accused of purchasing stolen Desjardins customer data from Sébastien Boulanger-Dorval, a former Desjardins marketing employee, and using it to carry out fraud schemes. Boulanger-Dorval, 42, was arrested in 2024 and charged with fraud, identity theft, and the illegal sale of personal data—allegedly to settle debts. He was identified as the primary suspect in the breach, having exploited his access to sensitive information while employed at the financial institution.
INCIDENT DETAILS -
TYPE
Data BreachFraudIdentity Theft
MOTIVATION
Financial GainDebt Repayment
IMPACT
Data Compromised: Desjardins members and customers data listsBrand Reputation Impact: HighLegal Liabilities: YesIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Personal InformationSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Yes
OCTOBER 2025
696Before Incident
SEPTEMBER 2025
694Before Incident
JUNE 2024
733Before Incident
Breach
01 Jun 2024Desjardins
Desjardins: Canadian fugitive wanted in Desjardins data breach investigation arrested in Mexico

Desjardins Data Breach

657After Incident
CRITICAL-76
DES1784263086
Quebec Fugitive Arrested in Mexico Over Desjardins Data Breach A Quebec man wanted for over two years in connection with the massive Desjardins data breach has been arrested in Mexico. Maxime Paquette, 40, was taken into custody by Mexican authorities in Cancun on Thursday after being sought since June 2024. Paquette had been listed among Quebec’s most wanted fugitives. Paquette remains detained in Mexico while extradition proceedings are underway to return him to Canada, where he faces charges including fraud over $5,000, identity theft, and trafficking in identity information. The arrest stems from investigations led by the Sûreté du Québec (SQ) under Portier and Project D, which probe the theft and circulation of personal data from the Desjardins breach one of Canada’s largest privacy violations. The breach, occurring between 2017 and 2019, exposed the personal information of nearly 10 million Desjardins members and clients. The SQ credited Mexican authorities, Interpol, the RCMP, Quebec City police, and other international partners for their role in the arrest.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Fraud, Identity Theft, Trafficking in Identity Information
IMPACT
Data Compromised: Personal information of nearly 10 million members and clientsBrand Reputation Impact: HighIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Personal informationNumber Of Records Exposed: Nearly 10 millionSensitivity Of Data: HighPersonally Identifiable Information: Yes
JUNE 2021
749Before Incident
Breach
27 Jun 2021Desjardins
Desjardins: Mexican authorities arrest Quebec fugitive linked to Desjardins data breach, police say

Desjardins Data Breach Fraud

673After Incident
CRITICAL-76
DES1784226588
Quebec Fugitive Arrested in Mexico Over Desjardins Data Breach Fraud Mexican authorities have arrested Maxime Paquette, a 40-year-old fugitive wanted by Quebec provincial police (Sûreté du Québec, SQ) in connection with the 2019 Desjardins data breach. Paquette, one of Quebec’s most wanted individuals, was detained in Cancún and will remain in custody while extradition proceedings move forward for his return to Canada. Paquette faces multiple charges under the Criminal Code, including fraud exceeding $5,000, identity theft, and trafficking in identifying information. According to the SQ, he obtained and exploited Desjardins customer data from the 2019 breach, which exposed sensitive information including names, addresses, birth dates, social insurance numbers (SINs), and transaction habits of nearly 9.7 million Canadians. Between June 27 and June 30, 2021, Paquette was found in possession of stolen Desjardins data and allegedly sold it to multiple individuals and on the dark web. The SQ collaborated with Mexican authorities, Quebec’s public prosecution service, Interpol, and other international partners to secure the arrest. The 2019 Desjardins breach remains one of Canada’s largest data leaks, with long-term implications for affected customers. Paquette’s extradition and prosecution mark a significant development in the ongoing investigation.
INCIDENT DETAILS -
TYPE
Data Breach, Fraud, Identity Theft
MOTIVATION
Financial gain
IMPACT
Data Compromised: Names, addresses, birth dates, social insurance numbers (SINs), transaction habitsBrand Reputation Impact: SignificantIdentity Theft Risk: High
DATA BREACH
Personally Identifiable Information (PII)Financial DataNumber Of Records Exposed: 9.7 millionSensitivity Of Data: HighData Exfiltration: YesPersonally Identifiable Information: Names, addresses, birth dates, social insurance numbers (SINs)
MAY 2019
794Before Incident
Breach
27 May 2019Desjardins
Desjardins: Final suspect in Desjardins data breach case arrested in Mexico: SQ

Desjardins Data Breach and Fraud Scheme

720After Incident
CRITICAL-74
DES1784220432
Final Suspect in Desjardins Data Breach and Fraud Scheme Arrested in Mexico The last fugitive in the multimillion-dollar fraud and data theft case involving Desjardins customers has been apprehended. Maxime Paquette, one of Quebec’s most-wanted suspects, was arrested in Cancún, Mexico, in a joint operation by the Mexican Navy and the Mexican Criminal Investigation Agency. He remains in Mexican custody pending extradition to Canada, where he faces charges including fraud over $5,000, identity theft, and trafficking of identities. The 2019 Desjardins data breach compromised the personal information of 9.7 million clients, which was later sold to cybercriminals for fraudulent schemes. Paquette is accused of using stolen Desjardins customer data obtained between March 2018 and September 2020 to conduct fraud and distribute the information on the dark web. Authorities also linked him to the possession of confidential Desjardins customer data exposed in the 2019 breach. Paquette’s arrest follows a two-year international manhunt involving Mexican authorities, the RCMP, and Interpol. His capture comes after the 2024 arrests of several other suspects in the SQ’s Portier investigation, including the alleged mastermind a former Desjardins marketing employee. Another fugitive, Juan Pablo Serrano, was arrested in Spain in November 2025. Investigations revealed systemic failures at Desjardins, with the Office of the Privacy Commissioner of Canada and Quebec’s Commission d’accès à l’information concluding in 2020 that the financial institution had neglected critical security weaknesses. The breach went undetected for over two years before police alerted Desjardins in 2019. Meanwhile, Laval police continue to search for a remaining suspect, Nassim Alikacem, in connection with the misuse of stolen data.
INCIDENT DETAILS -
TYPE
Data Breach, Fraud, Identity Theft
MOTIVATION
Financial gain, Identity theft, Fraud
IMPACT
Financial Loss: Multimillion-dollar fraudData Compromised: Personal information of 9.7 million clientsSystems Affected: Desjardins customer databasesOperational Impact: Regulatory scrutiny, legal actionsBrand Reputation Impact: SignificantLegal Liabilities: Fines, regulatory violationsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Personal information, Confidential customer dataNumber Of Records Exposed: 9.7 millionSensitivity Of Data: High (Personally Identifiable Information)Data Exfiltration: Yes (sold on dark web)Personally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Desjardins ?
?
What was Desjardins's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Desjardins's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Desjardins's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Desjardins's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Desjardins's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Desjardins's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Desjardins's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Desjardins's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Desjardins's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Desjardins's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Desjardins's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Desjardins's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Desjardins ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Desjardins's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?