A cybersecurity incident that affected the Kinsmen Foundation of Saskatchewan earlier this year is worse than initially thought. An investigation has found more personal data was compromised during the hack. In an update Thursday, the foundation said it discovered that social insurance numbers and health information required to process grant applications were also affected. Initially, the organization believed only donor contact info and email addresses had been affected. “We want to be clear: we have no evidence that any personal information has been misused. Still, we are notifying every affected individual personally and telling them what information of theirs was involved,” the update read. In April 2026, an unauthorized third-party accessed some of the foundation’s systems. Kinsmen notified its donors on May 20, saying the foundation informed police as soon as it discovered its systems had been breached. The organization also engaged third-party security firm Cyberscout to investigate and help beef up its security processes, according to the message at the time. In Thursday’s update, the foundation apologized to all those affected by the breach. “We also want to say, plainly: we are sorry,” the update read. “We built this organization on trust, generosity, and the goodwill of the communities we serve. We have learned that all Canadian organizations, including charitable organizations such as ours are potential targets for cyber-attacks such as these. It is our responsibility to make sure every person affected has the answers and support they need.” “A lot of this will end up on the dark web, and it can be used by bad actors to gain money in some way,” information technology expert Gareth McKee said. McKee is the CEO of Burn Orange Solutions. Burnt Orange helps train and protect companies from breaches similar to Kinsmen’s. McKee has been contracted to retrieve personal information and has even brokered deals with ransomware attackers. He says the most likely way a hacker gains access to a company’s data is from an employee clicking on a suspicious email link. “And then accidentally downloaded something — that’s where the main danger is,” McKee said. “It’s very important for organizations to make sure that they’re staffed are trained correctly.” McKee says workers should pause before clicking any link and carefully inspect emails to make sure there are no misspellings. He says unlike large corporations that spend millions of dollars on cyber security, smaller organizations may be vulnerable. Regardless, he suggests every company using the internet to protect itself. “An organization of any size, whether it’s a one-person company or its 200 people, should be getting specialist advice from managed security providers,” McKee said. The foundation says it is working with Transunion Canada to offer a year of complimentary credit monitoring to every person whose information was affected. McKee says once information is accessed, there’s not much a company can do, and credit checks may offer little comfort. “It’s closing the gate after the horse has bolted,” McKee said. There’s not a lot that these organizations can do once the data’s out there, because we don’t know what it’s going to get used for."