U.S.-based company (student information system) data breach: what happened and what to do
Last reviewed June 22, 2025 · 1 record on file · sources listed below
A data breach involving a student information system used across Canada has raised concerns. The federal privacy watchdog is seeking more information from the U.S.-based company behind the software.
If you have an account with U.S.-based company (student information system), assume the exposed details are circulating. The practical risk today is rarely the leak itself — it is the calls and messages that use those details to sound legitimate.
What we have on file
Every entry below is a catalogued record with its original source. We do not paraphrase beyond what the source reports.
What to do
- Change the password anywhere you reused itThe exposure matters most when the same password protects your email, because email is how everything else gets reset.
- Treat every call and text about this breach as a scam until proven otherwiseNo company will ask you for a one-time code, a PIN or a password. Hang up and call the number printed on your card.
- Read your statements for the next three monthsCard fraud usually starts with a small test charge. Catching that one is what stops the large one.
- Give your email account a password nothing else usesIt is the account that can reset all the others, so it is the one worth protecting first.
- Turn on Autodeposit for Interac e-TransferIt removes the security-question step that scammers try to guess. An e-Transfer cannot be reversed once deposited.
- Place a fraud alert with Equifax and TransUnionFree, and it forces extra verification before credit is opened in your name.
- Report losses to the Canadian Anti-Fraud Centre1-888-495-8501. Only 5 to 10% of fraud is ever reported, which is why the numbers you read are understated.
Questions people ask
Was my data in the U.S.-based company (student information system) breach?
Having an account alone does not confirm exposure. The reliable check is whether your email address appears in the leaked datasets in circulation — that takes seconds and does not require your password.
Is it too late to do anything?
No. Leaked personal details do not expire, and neither does the defence: a unique password on your email, and a fraud alert on your credit file, still work years later.
Will U.S.-based company (student information system) contact me?
They may. But scammers contact people too, using exactly these breach details to sound convincing. Never act on an inbound call or text — call back on a number you already had.