SecurityBrief Canada - Technology news for CISOs & cybersecurity decision-makers
Canada
Canada faces ransomware rate more than twice global

Canada faces ransomware rate more than twice global

Fri, 18th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Canadian organisations are facing cyberattacks at more than twice the global ransomware rate, according to Check Point Research. Its latest threat data also showed an average of 1,664 cyberattacks a week against organisations in Canada over the past six months.

Ransomware affected 18.2% of Canadian organisations during that period, compared with a global average of 9.0%. The rate peaked at 27.3% in late July, and Canada ranked as the fourth most affected geography by ransomware activity over the last 30 days.

The figures point to a threat environment in which attackers are intensifying pressure across sectors and relying heavily on web-based delivery methods. Almost 60% of malicious files targeting Canadian organisations in the last 30 days were delivered through the web, compared with 40.3% through email.

PDFs were the most common malicious file type across both channels, accounting for about 44.7% of malicious web files and 40.7% of malicious email files detected in Canada.

Sector pressure

Consumer-facing businesses appear to be under particular strain. In the last month, the Consumer Goods & Services sector recorded the highest attack volume, with an average of about 3,565 weekly attacks per organisation.

The report also highlighted the role of software weaknesses in giving attackers access to systems and data. Information disclosure was the most common exploit type in Canada, affecting about 68% of organisations, followed by remote code execution at 63% and authentication bypass at 53%.

This suggests many organisations remain exposed through known technical gaps even as they improve detection of incoming threats. Attackers appear to be combining direct disruption, such as ransomware, with exploit techniques that can expose sensitive information or create deeper access inside networks.

Web delivery

The dominance of browser-based delivery adds to concerns for employers whose staff work across multiple digital tools rather than relying mainly on email. Security teams have traditionally focused heavily on inbox filtering, but the data suggests web traffic, cloud applications and other online workspaces remain important routes for malicious files.

The concentration of web-delivered malicious files suggests organisations should look beyond email when assessing cyber risk. The research also argued that simply identifying vulnerabilities is not enough if remediation does not follow quickly.

For businesses, the figures underline the operational and financial risks tied to ransomware in particular. A successful attack can halt services, lock critical systems and create pressure to pay through both business interruption and the threat of stolen data being published.

Robert Falzon, Head of Engineering at Check Point Software Canada, said the country presents attractive conditions for extortion groups because of its mix of valuable data, interconnected suppliers and the high cost of downtime.

"Canada offers ransomware groups an attractive combination: valuable data, connected supply chains and organizations where downtime becomes expensive quickly. Smaller businesses often have limited security resources, while a compromise at a shared supplier can affect many customers very quickly. Criminals exploit those conditions through stolen credentials and unpatched systems, then use disruption or stolen data to create relentless pressure to pay. The priority is to eliminate those entry points and prevent attacks before they interrupt the business," Falzon said.

Risk priorities

The research identified three areas Canadian organisations should prioritise. The first is to focus remediation on exposures that carry the greatest real-world risk rather than treating all vulnerabilities as equally urgent.

The second is to protect the full digital workspace, including browsers, software-as-a-service applications, endpoints and other day-to-day environments used by staff. The third is to strengthen ransomware defences to stop intrusions early and contain attackers if an initial compromise succeeds.

More broadly, the findings reflect how cyber threats are becoming faster and more persistent, with criminals using stolen credentials, unpatched systems and common file formats to gain entry. In that environment, the speed at which organisations can reduce exposure matters as much as their ability to identify it.