Printer-friendly version
PDF version A Laval police investigation, which Desjardins has been closely involved with, has revealed that the personal information of 2.9 million members (2.7 million personal members and 173,000 business members) was disclosed to individuals outside Desjardins without authorization.
The investigation quickly traced the leak to a single source: an ill-intentioned employee who acted illegally and betrayed the trust of their employer. That person was fired.
In light of these events, additional security measures have been put in place to ensure all our members' personal and financial data remains protected.
You should also know that:
- The following information was not compromised: AccèsD passwords (for both personal and business accounts), security questions and PINs.
- Desjardins has not been the target of a cyberattack. Our computer systems have not been compromised in any way by this incident.
- We have not seen a spike in fraud cases involving our members' accounts in recent months.
We understand that this is a worrying situation. We sincerely regret the inconvenience it has caused. Your assets and accounts at Desjardins are protected—you won't suffer a financial loss if unauthorized transactions are made in your Desjardins accounts as a result of this situation.
What we've already done
- We introduced additional monitoring and security measures to protect your personal and financial information.
- We notified the following authorities: the Office of the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec and the Autorité des marchés financiers.
- We fired the employee responsible for the leak.
- We enhanced our procedures to confirm your identity when you call us.
What we're doing right now
- We're carefully monitoring the activity in all our members' accounts.
- We're taking additional steps to confirm our members' and clients' identities when they call their Desjardins caisse or our AccèsD call centre.
- We're communicating directly with every member who's been affected to explain what's happened and what they can do.
- We're continuing to work with the police.
- We're working with experts to keep our members' information protected.
What you can do
If you've received a letter from us
That means you're one of the impacted members.
We're offering you a 5-year credit monitoring plan, paid for by Desjardins. The service includes daily access to your credit report, alerts of key changes, and identity theft insurance.
Your personal activation code is in the letter you received. You have until October 31, 2019, to activate the service on Equifax's website: http://myservices.equifax.ca/prem - This link will open in a new window..
Please note that you'll need an email address or cellphone number to activate the service.
- If you have questions or concerns, you can reach us between 9:00 a.m. and 9:00 p.m., 7 days a week, at 1-800-CAISSES (1-800-224-7737).
If you haven't received a letter from us
That means you're not one of the members who has been affected by the situation—but it's always a good idea to be vigilant.
- Be suspicious of any emails and text messages you receive that ask you to provide personal information. Desjardins will never send you unsolicited emails or text messages asking for personal information.
- Make sure all your recent account activity is legitimate.
If you administer a business or estate account, or if you have power of attorney for an account
You'll receive a letter for each impacted account. As a result, you may receive more than one letter. We decided to proceed in this manner to make sure you were notified as quickly as possible. Consolidating our mailing lists would have taken extra time that we didn't want to waste.
When it comes to your personal information, you can never be too cautious. Visit the
Security section of our website to learn more about how to improve your online security practices.