Ransomware victim disclosure
← All victimsCanadian Nurses Association
Claimed by Snatch · listed 3 years ago
Status timeline
- ListedMay 22, 2023
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- Canada
- Sector
- Non-Profit
- Listed on leak site
- May 22, 2023
About the victim
AI dossier — public-source company profileThe Canadian Nurses Association (CNA) is a national non-profit organization representing approximately 460,000 regulated nurses across all 13 Canadian provinces and territories. Founded in 1908 and headquartered in Ottawa, Ontario, it is the sole national focal point for the nursing profession in Canada. CNA leads health policy development, professional certification, and advocacy at the national level.
- Industry
- Non-Profit Professional Nursing Association
- Address
- Suite M209, 1554 Carling Ave, Ottawa ON K1Z 7M4, Canada
- Employees
- 51-200
- Founded
- 1908
Attack summary
Severity: critical — The CNA holds personal and professional data on up to 460,000 regulated nurses across Canada, constituting PII at significant scale. Data has been published (data_published status), confirming exfiltration of data from a national health-sector professional body, which likely includes regulated PII and health-profession credentials.The Snatch ransomware group claims to have attacked the Canadian Nurses Association and has published data (disclosed status: data_published), indicating exfiltration of organizational data. No ransom amount or specific data volume was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Health policy documents
- Member/nurse registration data
- Organizational internal records
- Personal information of regulated nurses
- Administrative and financial records
What the group claims
CNA is a powerhouse nursing organization leading the development of health policy across Canada. Representing Canada's 460,000 regulated nurses, across all 13 provinces and territories, we're the only focal point for the profession on the national stage — and have been since 1908.
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

