Ransomware victim disclosure
← All victimsCommission de la construction du Quebec
Claimed by Qilin · listed 4 days ago
Status timeline
- ListedSep 1, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- Canada
- Sector
- Government & Defense
- Listed on leak site
- Sep 1, 2026
About the victim
AI dossier — public-source company profileCommission de la construction du Québec (CCQ) is a Quebec government regulatory body that oversees the construction industry. It manages worker qualifications, apprenticeships, labour relations, benefits administration (including health and pension schemes), and enforces construction industry regulations under Law R-20.
- Industry
- Government & Regulatory / Construction Industry
Attack summary
Severity: high — CCQ is a critical government regulatory body managing sensitive personal data (worker identities, health/pension records, salary information) at scale across Quebec's construction industry. Confirmed data publication by Qilin indicates successful exfiltration of regulated PII and occupational records. Lack of operational disruption details prevents 'critical' classification, but scale and sensitivity of government worker/benefits data warrants 'high'.Qilin ransomware group claims to have attacked CCQ. The group's leak post content was not provided (marked 'N/A'), and the disclosed status is 'data_published', but no specific details of exfiltrated data or operational impact are stated in the available information.
Data the group says was taken
AI dossier — extracted from the leak post- Construction worker records
- Apprenticeship and qualification files
- Employee benefits and pension data
- Health insurance information (MÉDIC Construction)
- Salary and payroll records
- Employer and contractor registration data
- Labour relations and collective agreement records
What the group claims
N/A
Screenshot of the leak post

Sources
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

