Fair Vote Canada 2024 Data Breach

Fair Vote Canada Electoral Reform Organization Breach (2024): 134K Member Contact Records Exposed

Nonprofit · Political advocacy and electoral reform · Civic engagement and policy advocacy group · Canada

Fair Vote Canada Electoral Reform Organization Breach (2024): 134K Member Contact Records Exposed

Canadian electoral reform advocacy organization

Confirmed · ObscureIQ Intelligence
Limited DisclosureThis breach is handled differently. Because being connected to it can itself be sensitive, we do not confirm anyone’s presence publicly. Use the private exposure check at the bottom of this page.
Breach Risk Index i
65/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Restricted
Being associated with this breach can itself be harmful. Disclosure is limited and presence is not confirmed to unverified parties.
134KRecords
2024Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
AddressPhysical address
Classification Tags
Researcher disclosureCloud MisconfigurationGovernmentMembers2024

Breach Summary

Fair Vote Canada, the Canadian national citizens' campaign for proportional representation, suffered a data breach that came to public attention on March 2, 2024. The incident was caused by a well-meaning volunteer who had been granted temporary access to historical organizational data for a specific task and who inadvertently moved a 2020-era supporter dataset to an external website that lacked adequate security controls. The data remained exposed at the unauthorized location until Fair Vote Canada discovered the issue and acted to remove and delete the exposed records. The breach was indexed by Have I Been Pwned on October 21, 2024 and was reported in Canadian and international tech press shortly after. The breach affected approximately 134,336 unique email addresses and the underlying supporter records associated with them. Compromised fields included names, email addresses, phone numbers, physical addresses, and, for some individuals, date and amount of donations made to Fair Vote Canada. No financial credentials or passwords were exposed. The dataset reflected supporter records as of 2020, meaning some individuals on the list may no longer have been active Fair Vote Canada supporters at the time of disclosure. For affected supporters, the practical risk profile combines standard contact-data exposure with political-advocacy-specific concerns. The combination of name, address, phone number, and email address supports phishing and social-engineering campaigns. More distinctively, inclusion in the dataset confirms a Fair Vote Canada supporter relationship and, for donor-list individuals, confirms financial support for proportional-representation advocacy. This creates political-affiliation mapping risk, in which actors with political opposition to electoral reform could use the data to identify, profile, or target Fair Vote Canada supporters. Reported risks include targeted political harassment, doxxing, and influence-operation targeting of identified electoral-reform supporters. Affected individuals should remain alert to unsolicited contact referencing Fair Vote Canada or electoral-reform topics, monitor for unusual political messaging targeting their address or phone, and consider Have I Been Pwned exposure scans for any reused email or password combinations.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

134K records analyzed

About Fair Vote Canada

Fair Vote Canada is a Canadian national nonpartisan citizens' campaign that advocates for proportional representation and broader electoral reform in Canada. Founded in 2001, the organization operates as a registered Canadian nonprofit and coordinates volunteer chapters, public-education campaigns, petitions, and grassroots advocacy work in support of changing Canada's first-past-the-post electoral system. Fair Vote Canada is co-chaired by Valerie Brooks and Steve Hindle. As a political-advocacy nonprofit, Fair Vote Canada maintains supporter and donor records including names, contact details, donation history, petition signatories, and engagement records tied to political advocacy activities, public-comment campaigns, and electoral-reform organizing.

Why They Hold Your Data

Maintains supporter and member data including names, email addresses, and engagement records tied to political advocacy activities, petitions, and campaign communications.

Recent Developments

Following the breach, Fair Vote Canada acknowledged the incident publicly and apologized to affected supporters and donors. Co-Chairs Valerie Brooks and Steve Hindle issued a public statement expressing regret and emphasizing transparency in their response. Fair Vote Canada removed the exposed data from the unauthorized location, restricted database access to staff and contractors only, and adopted stricter digital security procedures going forward. Have I Been Pwned indexed the breach on October 21, 2024, and noted that 83 percent of the affected email addresses had previously appeared in other breaches. Queen's University IT Services subsequently force-expired passwords for any Queen's account holder whose credentials appeared in connection with the leak.

Data Points Exposed

5 verified field types
Donation History
Email Address
Full Name
Phone Number
Physical address High

Breach Impact

The institutional impact on Fair Vote Canada was meaningful given the political-advocacy context and the donor-data sensitivity, though the organization avoided regulatory penalties because the incident was an inadvertent volunteer error rather than a malicious breach. Canadian privacy authorities under PIPEDA were notified, and Fair Vote Canada's disclosure was generally regarded as transparent and timely. Reputational impact concentrated within the Canadian electoral-reform community, where donor trust is essential to ongoing fundraising and grassroots organizing. The case has been cited within Canadian nonprofit governance discussions as a leading example of volunteer-access risk and the importance of role-based data access controls. Some donors and supporters expressed anxiety about the political-affiliation implications of the leak, particularly given that donor-history data confirms financial support for a specific political-reform position.

Exploitation & Downstream Threats

• SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

A government-linked breach: official identifiers and citizen records support identity fraud and credible authority-impersonation. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  2. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  3. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
RD
Threat Actor: Researcher disclosure
Threat actor

Attribution based on available breach intelligence.

Read the full threat-actor profile →

Protect Yourself

Protect Yourself: Limited Disclosure

Check If You’re Affected: Verification Required

Because being associated with this breach can itself be harmful, we do not confirm whether anyone appears in it to unverified parties. Verify your identity to privately check whether your own data appears in this breach or related indexes.

We will only reveal whether a specific person appears in this breach to that person.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation