Threats · Municipalities
Municipalities and ransomware: a recurring target
Why municipalities and local public bodies keep coming back in ransomware attacks, what the adversary wants from them, and what a small IT team does first.
By Sentrix · Published 2026-10-01
On a Monday morning, in a municipality of a few thousand residents, the screens at town hall show a ransom demand. Payroll, tax accounts, permits and the phone system are down. The IT team is two people, sometimes a single supplier. There is nothing exceptional about this scenario: local public bodies keep coming back in the official assessments, for reasons that have more to do with the adversary than with the size of the target.
What the sources say
In its National Cyber Threat Assessment 2023-2024, the Canadian Centre for Cyber Security notes an increase in threat activity against municipal and provincial governments: it reports "over 100 cases of cyber threat activity targeting Canadian municipalities since the beginning of 2020". Most cases involved social engineering, unauthorized network access or the deployment of malicious code, such as ransomware.
The 2025-2026 edition puts ransomware first: it is the top cybercrime threat facing Canada's critical infrastructure, and Canadian incidents known to the Centre have grown, on average, 26% year over year since 2021.
The Ransomware Threat Outlook 2025 to 2027 describes, without naming them, two cases in the Canadian public sector. In the first, services were unavailable for months; the actors had remained dormant in the network for months before exfiltrating personal, medical and financial information, and the entity chose to rebuild its systems rather than pay. In the second, the organization recovered most of its services within days from its backups, without paying; certain systems still remained unusable for months, with costs estimated in the millions of dollars.
What the adversary wants
Money. The Centre assesses that ransomware actors operating against Canadian targets are "almost certainly opportunistic and financially motivated". Three levers explain why a local body suits them.
- Service disruption. According to the 2025-2026 assessment, critical infrastructure is an attractive target because these entities are perceived as more willing to pay large ransoms to prevent disruptions to critical operations. A body that cannot suspend its services faces the same calculation.
- Residents' data. According to the Ransomware playbook (ITSM.00.099), the actor encrypts the data, deletes connected backups and often steals the organization's data, then threatens to leak it. The 2023-2024 assessment notes that a compromise against any level of government can implicate residents' personal information, service continuity and trust in the institutions.
- Defences seen as weak. The same playbook states that small and medium-sized organizations are targeted because actors consider their security measures to be weaker. The Outlook adds that some groups mostly want to increase the number of posts on their leak sites, regardless of victim size.
Why it matters in Quebec
Data theft triggers a second obligation, separate from recovery. The Quebec government's page on confidentiality incidents sets out what sections 63.8 to 63.11 of the Access Act require of a public body: promptly take reasonable measures to reduce the risks, notify the Commission d'accès à l'information and the persons concerned when the incident presents a risk of serious injury and keep a register of all incidents. Municipal bodies are defined in section 5 of that same Act.
A municipality is not alone, though: the ministère de la Cybersécurité et du Numérique lists municipalities and other municipal bodies among the entities to which it may provide its services.
What to do first, in order
For a team of two or three people, the order matters more than the length of the list. The technical measures come from the Centre's two guides.
- Put two backups out of reach. The playbook recommends two or more backups stored offline, inaccessible from the network or the Internet, and a schedule to test them (for example, monthly).
- Close the common doors. Regular updates, multi-factor authentication, caution with phishing: the basic practices the Outlook retains.
- Cut down administrator accounts. The playbook says to limit them to the people who need them and to create separate accounts for email and everyday work.
- Write the plan on one page. Who decides, who calls, through which channel. The playbook says to assume the actor is still on the network and to set up a communication method the actor cannot access.
- On the day, isolate, then report. Determine what is infected, disconnect those systems from the Internet and the internal network, then report the attack to local law enforcement, the Canadian Anti-Fraud Centre and the Cyber Centre (My Cyber Portal).
- Handle the data question in parallel. Assess the risk of injury, record the incident in the register, notify the Commission d'accès à l'information and the persons concerned if the risk is serious.
- Do not count on the ransom. According to the Outlook, there is no guarantee that the actors will unlock systems or return stolen data, and they can use it to revictimize the organization.
The next step
Ask two questions this week: where is the backup copy the network cannot reach, and who do we call at three in the morning? If either answer is missing, that is your first job. Our incident response page describes how to prepare that plan before the incident.
Sources
- Canadian Centre for Cyber Security, National Cyber Threat Assessment 2023-2024
- Canadian Centre for Cyber Security, National Cyber Threat Assessment 2025-2026
- Canadian Centre for Cyber Security, Ransomware Threat Outlook 2025 to 2027
- Canadian Centre for Cyber Security, Ransomware playbook (ITSM.00.099)
- Gouvernement du Québec, Incident de confidentialité (Access Act, sections 63.8 to 63.11, in French)
- Gouvernement du Québec, Clientèles du ministère de la Cybersécurité et du Numérique (in French)
Frequently asked questions
- Why would a ransomware group care about a small municipality?
- Because the adversary is after a payment, not a prestigious target. The Canadian Centre for Cyber Security assesses that ransomware actors are almost certainly opportunistic and financially motivated. Its Ransomware playbook adds that small and medium-sized organizations are targeted because their security measures are considered weaker, and some groups mostly want to grow the number of victims posted on their leak sites.
- Should a municipality pay the ransom?
- The decision belongs to the organization, but the Canadian Centre for Cyber Security spells out the risks: paying will not guarantee access to encrypted data or systems, and there is no guarantee that stolen data will be returned. Before even considering payment, playbook ITSM.00.099 says to report the cybercrime to the local police. Tested offline backups mean you do not depend on the adversary.
- Who should a ransomware attack be reported to in Quebec?
- The Canadian Centre for Cyber Security asks victims to report the attack to local law enforcement, the Canadian Anti-Fraud Centre and the Cyber Centre itself, through My Cyber Portal. If personal information is involved and the incident presents a risk of serious injury, Quebec's Access Act also requires notifying the Commission d'accès à l'information and the persons concerned. The incident goes in the register in every case.
Let's talk about your compliance program.
Last updated: 2026-10-01
