Cybersecurity Breach: MOVEit costs N.S. taxpayers more than $3 million; personal info from thousands still at risk
More than 165,000 letters have been sent to Nova Scotians caught up in the MOVEit global cybersecurity breach.
The breach took place between May 30 and May 31, and was first reported by the Nova Scotia government a few days later.
The province says $2.85 million has been spent so far for credit monitoring services related to the online hack.
That is in addition to the $240,000 paid by Nova Scotia to IBM following the breach for incident response support.
IBM remains on retainer, which costs $5,600 a month to ensure that they're available immediately if needed.
In a news release Thursday, Nova Scotia’s Cyber Security and Digital Solutions Minister Colton LeBlanc said once the province discovered the breach, the goal was to notify those impacted as quickly as possible so they could take steps to protect their identity.
“We've now finished that process," said LeBlanc. "Now, we can turn our focus to setting out the lessons we've learned and ensuring departments are doing what they need to do to keep Nova Scotians' personal information safe.”
The province offered five years of credit monitoring and fraud protection to people whose sensitive personal information was stolen.
In an email late Thursday afternoon, the province said to date, there have been no confirmed financial losses or confirmed claims of information being used to commit an offence using personal information obtained through the breach.
There have been no confirmed government department losses related to the breach.
SOFTWARE COMPANY
The cybersecurity breach involved a file transfer service called MOVEit that is used around the world by the private sector and governments.
The software is made by Burlington, Massachusetts-based company Ipswitch and allows organizations to transfer files and data between employees, departments and customers.
Progress Software, the parent company of Ipswitch, confirmed a vulnerability in its software in late May, saying the issue could lead to potential unauthorized access of users' systems and files.
After the company notified the government of Nova Scotia of a critical vulnerability within its system, the province took the service offline and installed a security update before bringing it back online.
The province continues to use MOVEit, which it says is essential to delivering core government services.
In August, the province said certified teachers born in 1935 or later were among those whose personal information was stolen, which included personal details about deceased people.
A group known as Clop, which claimed to be behind the attack, said they deleted all the stolen data from governments, cities, and police services but are keeping information from private companies.
In an interview with CTV near the end of June, cybersecurity expert Scott Beck questioned whether the word of this group can be trusted.
“There’s no way to know if they’ve actually deleted the data or not,” Beck said.
Beck suggested people still monitor their accounts for unusual activity.
N.S. government quick facts:
- more than 118,000 letters with TransUnion credit monitoring codes have been sent to people whose sensitive personal information, such as social insurance numbers or banking information, was stolen in the breach
- just over 47,000 letters without credit monitoring codes have been sent to Nova Scotians who had less sensitive information stolen, which put them at lower risk of identity theft
- more than 29,000 people have signed up for credit monitoring
- credit monitoring codes expire Oct. 31 for those who have received them
For more Nova Scotia news visit our dedicated provincial page.
CTVNews.ca Top Stories

Ibrahim Ali found guilty of killing 13-year-old girl in B.C.
A jury has found Ibrahim Ali guilty of killing a 13-year-old girl whose body was found in a Burnaby, B.C., park in 2017.
Protests at UN climate talks, from Israel-Hamas war to detainees, see 'shocking level of censorship'
Activists designated Saturday a day of protest at the COP28 summit in Dubai. But the rules of the game in the tightly controlled United Arab Emirates meant sharp restrictions on what demonstrators could say, where they could walk and what their signs could portray.
Marathon Conservative carbon tax filibuster ends after nearly 30 consecutive hours of House votes
The Conservative-prompted filibuster in the House of Commons ended Friday night, after MPs spent nearly 30 hours voting non-stop on the government's spending plans.
Israel presses on with Gaza bombardments, including in areas where it told civilians to flee
Israeli warplanes struck parts of the Gaza Strip overnight into Saturday in relentless bombardments, including some of the dwindling slivers of land Palestinians had been told to evacuate to in the territory's south.
CSIS boss apologizes for response to rape claim, revamps anti-harassment plans
Canada's spy chief has apologized to staff for his response to rape and harassment allegations in the agency's British Columbia office.
Observers see OPEC 'panicking' as COP28 climate talks focus on possible fossil fuel phase-out
Veteran negotiators at the U.N. climate talks Saturday said that the push to wean the world from dirty fossil fuels had gained so much momentum that they had poked a powerful enemy: the oil industry.
Ryan O'Neal, star of 'Love Story,' 'Paper Moon,' 'Peyton Place' and 'Barry Lyndon,' dies at 82
Ryan O'Neal, the heartthrob actor who went from a TV soap opera to an Oscar-nominated role in 'Love Story' and delivered a wry performance opposite his charismatic 9-year-old daughter Tatum in 'Paper Moon,' died Friday, his son said.
'Very unusual and unique find': Stomach contents of dinosaur found preserved in Alberta
Alberta's Royal Tyrrell Museum of Palaeontology says stomach contents have been found preserved inside a fossilized tyrannosaur.
Peek inside Joe Biden's campaign fundraisers, where big money mingles with old jokes in swanky homes
If you're a Democrat with money to burn and friends in high places, you can spend thousands on tickets to a fundraiser with President Joe Biden. If not, keep reading to see what you're missing.