On August 24, 2026, the Commission de la construction du Québec (CCQ) was hit by a cybersecurity incident. Its online and telephone services were quickly disrupted. A few days later, the scope of the incident became clearer: it was indeed a cyberattack, and personal information belonging to clients and employees had been stolen.
According to La Presse, approximately 350,000 people may have been affected. Potentially sensitive information includes dates of birth and social insurance numbers, although the nature of the compromised data varies from one individual to another.
La Presse also reported that the attack was claimed by Qilin, a Russian-speaking cybercriminal group associated with ransomware and extortion. Independent ransomware monitoring services have also listed the CCQ among the victims claimed by the group.
Beyond the scale of the incident, this cyberattack raises an important question for Quebec business leaders:
If your company were hit by the same kind of attack tomorrow morning, would you be ready?
A Cyberattack Is No Longer Just About Encrypted Files
For years, the typical ransomware scenario seemed relatively straightforward: a hacker gains access to a network, encrypts the company’s files and demands a ransom to restore them.
Today’s reality is far more concerning.
Groups such as Qilin are associated with what is known as double extortion. Cybercriminals can steal data before encrypting systems. This gives them two forms of leverage: disrupting operations and threatening to publish the stolen information.
For businesses, that distinction is critical.
A solid backup strategy may allow you to restore servers. But it cannot “recover” personal information that an attacker has already copied and taken outside the organization.
Once the data has left your environment, the problem changes entirely.
The Real Cost Appears When the Business Stops Operating
The CCQ incident also highlights an often underestimated consequence of cyberattacks: operational disruption.
After discovering the incident, the CCQ suspended several services while its teams secured and analyzed its IT environment. The organization had to implement temporary measures and regularly update workers, employers and partners as the situation evolved.
Full service restoration was announced for September 8, roughly two weeks after the incident was discovered.
Now imagine the same scenario in a small or mid-sized business.
No access to your management system. No access to certain documents. Employees unable to work normally. Customers calling. Suppliers waiting. Meanwhile, the management team is trying to understand what happened, coordinate with IT partners and determine which data may have been compromised.
The cost of a cyberattack therefore goes well beyond the ransom or the IT bill.
Businesses must also account for lost working hours, delayed sales, interrupted services, external specialists, customer communications and potential reputational damage.
350,000 Victims: Why Personal Information Is So Valuable
A database containing personal information can be particularly valuable to cybercriminals.
Why?
Because that information may remain useful long after the initial attack.
An email address can be used in phishing campaigns. Personal details can make fraudulent messages far more convincing. More sensitive information can increase the risk of identity theft.
This is one reason the CCQ is offering affected individuals credit and dark web monitoring services through Equifax, along with assistance in the event of fraud or identity theft.
For SMBs, there is an important lesson here: data that is retained unnecessarily is also risk that is retained unnecessarily.
Businesses should regularly ask themselves what information they hold, why they retain it, who has access to it and how long it actually needs to be kept.
Quebec’s Law 25 Adds Another Dimension
In Quebec, a cyberattack involving personal information is not simply an IT problem.
It is also a governance and compliance issue.
Under the obligations stemming from Law 25, businesses must maintain a register of confidentiality incidents and act quickly to reduce the risk of harm to the individuals concerned.
When an incident presents a risk of serious harm, the organization must also notify Quebec’s Commission d’accès à l’information and the individuals affected.
In other words, discovering an intrusion is only the beginning.
An organization needs to quickly determine what happened, what data was affected, who may be impacted and what actions need to be taken.
Improvising those decisions in the middle of a crisis is rarely a good strategy.
“We Have Backups” Is No Longer Enough
When businesses are asked whether they are prepared for a cyberattack, one answer comes up frequently: “Our data is backed up.”
That is essential. But it is only one part of the solution.
A true cyber resilience strategy should also include:
- isolated backups that are tested regularly;
- multi-factor authentication for critical accounts;
- rigorous management of access rights and administrative privileges;
- monitoring of devices and suspicious activity;
- timely vulnerability patching;
- employee awareness training on phishing and social engineering;
- a documented incident response plan;
- a business continuity procedure in case critical systems become unavailable.
One detail is especially important: test the plan.
An incident response document that has been sitting untouched in SharePoint for three years is not necessarily a functional plan.
Who calls the IT provider? Who decides whether certain systems should be shut down? Who communicates with employees? How do you reach key decision-makers if Microsoft 365 or the internal network is unavailable? Who contacts the cyber insurance provider? Who determines whether Quebec’s Commission d’accès à l’information must be notified?
Those questions are much easier to answer on a quiet Tuesday morning than in the middle of a cyberattack.
Cybersecurity Is Also a Business Continuity Issue
The CCQ incident is another reminder of a fundamental reality: cybersecurity is no longer solely the responsibility of the IT department.
When an attack can disrupt operations for days, compromise the personal information of hundreds of thousands of people and trigger legal obligations, it becomes a business risk.
Management therefore needs to be involved in preparing for it.
A business leader does not need to understand the technical workings of ransomware. But they should know the answers to a few straightforward questions:
How long can we operate without our systems?
Which data would cause the most damage if it were lost or stolen?
How long would it actually take us to restore operations?
Most importantly, have we ever tested those answers?
If no one in the organization can answer these questions clearly, the problem may not be technological. It may be a preparedness problem.
The Best Response to a Cyberattack Starts Before the Attack
The CCQ cyberattack will likely continue to be analyzed as the investigation progresses. Several technical details about how the attackers gained access to the environment have not yet been made public.
It would therefore be premature to draw conclusions about the precise cause of the incident.
One conclusion, however, can already be drawn.
No organization should wait until a cyberattack occurs to figure out how it will respond to one.
For a Quebec SMB, the goal is not to become invulnerable. No IT environment can guarantee zero risk.
The objective is to reduce opportunities for intrusion, quickly detect suspicious activity, limit the damage if an account or device is compromised, and restore operations as quickly as possible.
Because once an attack has started, it is already too late to begin writing the plan.
If the CCQ cyberattack has you wondering how your business would respond to a similar incident, MonTechnicien’s specialists can help you get a clearer picture. Our team helps Quebec SMBs protect their IT environments, prevent cyber threats and prepare for security incidents.