BreachOfPrivacy
Decisions/Federal (Canada)/Personal Information Protection and Electronic Documents Act/PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach
Office of the Privacy Commissioner of CanadaPersonal Information Protection and Electronic Documents ActPIPEDA Findings #2021-003Well-founded & resolved
Flag of Canada

PIPEDA Findings #2021-003: Security deficiencies at BMO lead to large-scale breach

Organization: Bank of Montreal (BMO)
Decision: Mar 30, 2021Published: Mar 30, 2021

This investigation report concerns a large-scale breach of personal information at the Bank of Montreal (BMO), affecting approximately 113,000 customers. The OPC found that BMO's online banking software had significant vulnerabilities, including issues with developer security testing, vulnerability management, and oversight/monitoring, which allowed attackers to access sensitive data such as financial account numbers and SINs. BMO has since implemented substantial improvements to its security safeguards.

  • Adequacy of BMO's technical safeguards to protect personal information.
  • Effectiveness of BMO's developer security testing and evaluation processes.
  • Sufficiency of BMO's vulnerability management protocols.
  • Appropriateness of BMO's oversight and monitoring capabilities for detecting cyberattacks.

Complaint well-founded, but resolved through corrective actions.

The OPC found that BMO contravened PIPEDA by failing to implement appropriate safeguards commensurate with the sensitivity of the personal information held. However, the finding was resolved because BMO made significant improvements to its security practices and technical safeguards following the breach.

AI-generated summary for reference only. Always verify against the official decision ↗

Recommended action / remedy

BMO was required to implement significant improvements to its security protocols, systems, testing, and operations to address the identified deficiencies.

Statutory provisions cited
  • Principle 4.7 PIPEDA
  • Principle 4.7.1 PIPEDA
  • Principle 4.7.3 PIPEDA

This summary is informational only and not legal advice.