Ransomware victim disclosure
← All victimsCanadian Mental Health Association
Claimed by Storm · listed 4 days ago
Status timeline
- ListedAug 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Storm
- Status
- Data leaked
- Country
- Canada
- Sector
- Healthcare
- Listed on leak site
- Aug 14, 2026
About the victim
AI dossier — public-source company profileThe Canadian Mental Health Association is a national mental health charity providing advocacy, education, research, and support services to persons experiencing mental illness across Canada. Headquartered in Toronto and Ottawa, CMHA operates a federated network of provincial divisions and regional branches delivering peer support, crisis intervention, workplace mental health programs, and recovery services.
- Industry
- Mental Health Services & Advocacy
- Address
- 595 Montreal Road, Suite 303, Ottawa, ON K1K 4L2 Canada; 250 Dundas Street West, Suite 401, Toronto, ON M5T 2Z5 Canada
- Employees
- 5000-10000
Attack summary
Severity: high — Confirmed exfiltration of data from a healthcare organization handling sensitive mental health records and personal information of vulnerable populations, with disclosed status indicating data has been published. Healthcare data breaches involving mental health records are regulated and highly sensitive.Storm claims to have exfiltrated data from the Canadian Mental Health Association. The specific data types and operational impact are not detailed in the leak post.
What the group claims
The Canadian Mental Health Association provides mental health services and support. The Association offers advocacy, education, research, and services to persons experiencing mental illness throughout Canada and is headquartered in Toronto, Ontario. The company headquarters is located in 595 Montreal Road, Suite 303, Ottawa, ON K1K 4L2 Canada and 250 Dundas Street West, Suite 401, Toronto, ON, M5T 2Z5 Canada. 5K - 10K Employees
Sources
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

