The clients of the Centre for Newcomers came to Calgary for a fresh start. On July 17, 2026, they got something else: their personal records, immigration files, and sensitive status documents became part of a 380 GB haul claimed by the Interlock ransomware group. The organisation, a Calgary-based nonprofit providing immigration and settlement services across Alberta, has not disclosed whether it paid a ransom or when operations will fully recover.
The incident is not a one-off. It is a pattern, and the pattern has a name: human risk.
A sector that cannot afford to recover
Nonprofit immigration services sit at an uncomfortable intersection: they hold exceptionally sensitive client data (immigration status, financial information, family records) while operating with security budgets that rarely extend beyond a basic firewall and an annual password reminder. When Interlock’s operators gained access to Centre for Newcomers’ systems, they did not need a zero-day exploit. According to the Canadian Centre for Cyber Security’s Ransomware Threat Outlook 2025-2027, ransomware remains the top cybercrime threat to Canada’s critical infrastructure, with incidents growing across nearly every sector each year.
The average cost of a Canadian data breach reached CA$6.98 million in 2026, a 10.4 percent increase year over year. For a nonprofit operating on thin margins and donor trust, that figure is not a setback. It is a shutdown risk.
What the attackers were looking for
Interlock is not a new name in Canada. The group targets organisations that are data-rich but security-light, harvesting information that carries long-term value: immigration records can be used for identity fraud years after the initial breach, and HR planning documents expose salary and staffing details that feed pretexting attacks against employees and vendors alike. Understanding the human layer of cybersecurity helps explain why nonprofits keep ending up in these groups’ target lists: they are organisations that run on trust, and trust is exactly what social engineering exploits.
Mandiant’s M-Trends 2026 report offers context that should sit uncomfortably with every nonprofit IT lead. Email phishing has dropped to just 6 percent of initial access methods in 2025. Voice phishing (vishing) has surged to 11 percent overall and to 23 percent in cloud-related compromises. Attackers are no longer counting on a staff member clicking a bad link; they are picking up the phone, impersonating IT staff or service providers, and talking their way past MFA protections. The report notes that “the vast majority of successful intrusions still stem from fundamental human and systemic failures.”
Why Canadian nonprofits remain exposed
In our work with Canadian nonprofits, we consistently see organizations operating with security budgets a fraction of their commercial peers, while facing the same threat actors. The pattern in this story is one we encounter monthly: well-meaning staff, no formal training program, and a single click away from a crisis they cannot afford to recover from.
The Centre for Newcomers breach is a reminder that security awareness for nonprofits is not a luxury item reserved for commercial organisations with larger IT budgets. Settlement services, food banks, community health centres, legal aid organisations: these are the institutions ransomware operators actively target, precisely because their data is valuable and their defences are predictable.
What your organisation can do this week
Security awareness for nonprofits does not need to be expensive or complex to make a measurable difference. Three concrete steps your team can take now:
- Run a scenario-based training session on vishing. Ask staff what they would do if someone called claiming to be from your IT provider and asked them to reset their MFA codes. The answer to that call should not be automatic compliance.
- Map where your most sensitive data lives. For an organisation serving immigrants, that is client intake forms, status documents, and case files. If those are on a shared drive with no access controls and no offline backup, that is the gap attackers walk through.
- Review your incident response plan, or write one if it does not exist. POPP3R’s Security101 nonprofit program is built for organisations in exactly this position: practical, affordable, and designed for teams where cybersecurity competes with twenty other priorities.
The people Centre for Newcomers serves deserve organisations that can protect their data. That protection starts with taking security awareness for nonprofits seriously, before the group posts the next 380 gigabytes.