William BensonVIEW PROFILE →
The Ransomware Playbook Just Changed, And Most Canadian Businesses Haven't Caught Up
Ransomware gangs quietly rewrote their entire playbook, and the backup strategy that used to save Canadian businesses doesn't work against it anymore.
Ransomware gangs quietly rewrote their entire playbook, and the backup strategy that used to save Canadian businesses doesn't work against it anymore.
For years, the advice for surviving a ransomware attack was almost comforting in its simplicity: keep good backups, and if the worst happens, just wipe your systems and restore from a clean copy. Don't pay the criminals. Walk away. That advice used to work. It doesn't anymore, and a lot of Canadian business owners are about to find that out the hard way. Somewhere in the last two years, the criminals running these operations figured out something uncomfortable: your backup doesn't matter if they already have a copy of everything on your network, sitting on a server they control, with your name attached to a countdown clock. The Rules Changed, and Nobody Sent Out a Memo Here's the shift in plain terms. The old ransomware model was simple: break in, encrypt your files, demand payment for the decryption key. Annoying, expensive, disruptive, but survivable if you had backups. The new model, what security researchers now call double or even triple extortion, adds a step that makes backups almost beside the point. Attackers get into your network, quietly copy your most sensitive files first, then encrypt everything, and only then send the ransom note. Now you're not just locked out of your own systems, you're staring down the threat of your customer data, financial records, or internal emails getting published on the open internet if you don't pay, whether or not you can restore your systems yourself. One Canadian cybersecurity firm summed up where things stand in blunt terms this year: encryption-only ransomware is basically dead. The 2026 version of an attack steals first, encrypts second, and threatens to publish third, turning your reputation into the second hostage alongside your data. The 2026 attacker exfiltrates first, then encrypts, then threatens to publish, and the second hostage is your reputation. The Numbers That Should Genuinely Worry You If you're tempted to think this is somebody else's problem, the data says otherwise, and it's not close. According to CIRA's 2025 survey, 24% of Canadian organizations were hit by ransomware in the previous 12 months. A separate industry report put that figure even higher, at 43% of Canadian organizations affected in the past year, once you count the broader universe of extortion-style attacks rather than classic encryption-only incidents. Statistics Canada's own numbers show ransomware identified as the attack method in 13% of businesses reporting a cybersecurity incident in 2023, up from 11% just two years earlier, a trend line moving in exactly one direction. The volume of pure extortion attacks, the kind where data gets stolen and no encryption happens at all, hit 6,182 cases across Canada in 2025, a 23% jump year over year. And insurer QBE Canada expects the number of publicly named ransomware victims to climb from around 5,010 in 2024 to more than 7,000 by the end of 2026, a five-fold increase since 2020. Canada itself isn't a bystander in the global numbers either: breach-tracking firm Breachsense found Canada accounted for 4.3% of all ransomware victims worldwide in January 2026 alone, placing it third behind only the United States and the United Kingdom.

Why "We'll Just Restore From Backup" Doesn't Cut It Anymore
This is the part that catches even well-prepared businesses off guard. A company can do everything right on the recovery side, tested backups, redundant systems, a documented incident response plan, and still end up in serious trouble, because the backup only solves half the modern ransomware problem. Restoring your systems gets your operations running again. It does absolutely nothing to stop the attacker from following through on a threat to leak your stolen customer data, trade secrets, or financial records to the public, or straight to your competitors, regulators, and customers.
That's the entire logic behind triple extortion: even a business with a flawless recovery plan still has a decision to make, because the leverage criminals hold has moved from "can you get your files back" to "can you afford the fallout if this data goes public." For a professional services firm, a healthcare provider, or a law office bound by client confidentiality obligations, that second threat can be far more damaging than a few days of downtime ever was.
The part that might actually surprise you: most Canadian businesses don't pay
Despite the scary headlines, Statistics Canada found that 88% of Canadian business ransomware victims in 2023 did not pay the ransom, a genuinely encouraging number. Of the businesses that did pay, 84% paid under $10,000, but a small, brutal tail end, about 4%, paid more than $500,000. Average ransom payouts in Canada reached $1.13 million in 2023, a figure skewed heavily by a handful of massive enterprise payouts rather than reflecting what a typical small business actually faces. Total recovery costs from cyber incidents across Canada still hit $1.2 billion in 2023, double what they were just two years earlier, proof that even businesses who refuse to pay are absorbing serious costs just getting back on their feet.

Who's Actually in the Crosshairs
Ransomware crews aren't targeting randomly, and the sector breakdown tells you a lot about how they think. Globally, government and administrative systems topped the list as the most targeted sector between August 2023 and August 2025, accounting for 19% of all incidents, followed by IT and telecommunications at 18%, with manufacturing, logistics, and transport together making up another 13%. More recent monthly tracking from January 2026 showed manufacturing as the single most-targeted sector with 57 victims, followed by construction, technology, and healthcare.
The pattern underneath those numbers is consistent: attackers go after organizations where downtime is unbearable, hospitals that can't function without their systems, manufacturers with time-sensitive supply chains, government bodies handling essential services, because that operational pressure makes victims far more likely to consider paying quickly rather than fight it out. It's also worth noting that a growing share of these attacks now hit small and mid-sized businesses specifically, which the data consistently shows carry the lowest baseline security maturity of any organization size, and least often, absorb the majority of overall damage.

The AI Wildcard Making All of This Worse
Here's a genuinely uncomfortable twist: the same generative AI tools Canadian businesses are rushing to adopt for legitimate work, 78% of organizations report using AI in at least one business function, are being weaponized right back at them. Industry reports describe GenAI threats manifesting as automated phishing campaigns that read far more convincingly than the clumsy scam emails of a few years ago, identity fraud, and deepfake scams designed to trick employees into wiring money or handing over credentials. Just as importantly, this technology is lowering the technical bar for entry into cybercrime altogether, letting less-skilled criminals launch attacks that would have previously required real technical expertise.

What Actually Works Against All This
The good news buried in all of this bad news: the actual entry points attackers use haven't changed much, even as their extortion tactics have gotten meaner. Stolen or reused passwords, unpatched devices sitting exposed to the internet, and employees clicking things they shouldn't still account for the overwhelming majority of successful break-ins. The Canadian Centre for Cyber Security's Baseline Cyber Security Controls, aligned with the broader CIS Controls v8.1 framework, give small and medium organizations a genuinely achievable starting point: multi-factor authentication, disciplined patching, immutable backups that attackers can't tamper with, and an incident response plan that's actually been tested rather than just written down and forgotten in a drawer.
Canada has also started backing this up with policy. Bill C-8 passed in June 2026, and supplier flow-down clauses tied to cybersecurity requirements are already showing up in contract renewals across multiple industries, effectively forcing better security practices down through supply chains rather than leaving it purely voluntary. On the prevention side, the Canadian Centre for Cyber Security's pre-ransomware notification program issued 336 warnings to more than 300 Canadian organizations in 2024-2025 alone, catching intrusions before encryption or data theft happened, with estimated economic savings up to $18 million from those early warnings alone.

The uncomfortable truth for small businesses specifically
If there's one finding that deserves more attention than it gets, it's this: small and medium Canadian businesses report the lowest baseline security control maturity of any organization size, while simultaneously absorbing the majority of overall ransomware impact. Larger enterprises can afford dedicated security teams, expensive monitoring tools, and cyber insurance policies built for this exact scenario. A twenty-person accounting firm or a regional manufacturer usually can't, which is precisely why attackers increasingly see smaller Canadian businesses as the easier, more profitable target, not because the payout is bigger, but because the resistance is so much lower.







