On May 2, 2026, Canadian business process outsourcing firm Symcor appeared on the leak site of the Everest ransomware group in a listing claiming internal files were exfiltrated during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Symcor
Get alerted the next time Symcor files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Symcor’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Symcor, which provides cheque processing, statement production, and digital transaction services to major Canadian banks and financial institutions, had data taken by the attackers. The company, founded in 1996 and based in Mississauga, Ontario, handles large volumes of sensitive financial and customer information for its clients. Available reporting describes the incident as a ransomware attack in which internal files were allegedly exfiltrated, though the exact number of affected individuals remains unknown. The data exposed consists primarily of internal documents rather than a structured database of customer records.
Everest ransomware group listed Symcor on its leak site on May 2, 2026, following the pattern the group typically follows when victims do not pay. No confirmed deadline for further data publication has been widely reported, but such listings often signal that negotiations have failed and that samples or full datasets may be released.
Why This Matters for You and Your Family
If you or your family bank with any of the major Canadian institutions that rely on Symcor for statement production, cheque processing, or payment services, your personal financial documents could be among the internal files now in attackers’ hands. Even though the total number of people affected is not public, the nature of Symcor’s work means everyday customer statements, account details, and related records were likely present in the compromised environment. Financial data of this kind can be used for identity theft, loan fraud, or targeted scams that feel very personal.