Investigation reveals thousands had info exposed in P.E.I. arts centre data breach

The full impact of a data breach at Prince Edward Island’s largest arts centre is now clear. The results of a recently completed investigation show thousands of people had their personal information exposed.
The cyberattack was first reported by the Confederation Centre of the Arts in January. In February, officials confirmed it was a ransomware attack, which exposed some personal information held on the organization’s servers.
“A ransomware attack is where criminals will encrypt or scramble the data and systems of an organization preventing them from being able to access it or use it, essentially rendering it all useless,” said David Shipley, CEO of New Brunswick-based cybersecurity firm Beauceron. “Then they hold it for an extortion payment.”
The centre did pay a ransom to the attackers, but didn't disclose the amount paid.
The recently completed investigation into the breach found about 3,000 people were exposed, some just names and email addresses, but others had their date of birth and social insurance number exposed.
“The attack basically took down our entire IT infrastructure,” said Jodi Zver, Confederation Centre of the Arts’ chief financial officer. “We had to rebuild everything from the ground up, new servers, new everything. That took a very long time, and until we had that done we didn’t have access to the data that told us whose information was there.”
Officials say the affected people have been contacted, with the highest risk being offered credit monitoring and insurance.
This isn’t the first time something like this has happened in the region. The City of Saint John was hobbled after its information technology systems were targeted by a similar attack.
Experts say municipal governments and small non-profit organizations are easy targets.
“These organizations do not, generally, have IT teams and they certainly don’t have robust cybersecurity in place,” said Shipley. “So if you have the choice between going up against a global bank with a half a billion dollar security budget and few thousand eager cybersecurity professionals, or you can pick on the little kids.”
The Confederation Centre’s new system has improved backups and monitoring, as well as new information management policy.
“We’re not storing people’s personal information,” said Zver. “So if or when this happens again then we’ll be fine because we know the information wasn’t there for them to take.”
Officials say the box office and payroll system was not breached, so stored financial information should have remained secure.
The vast majority of successful cyberattacks are against people, not IT infrastructure. Attacks include getting members of an organization to click on a bad link or login to a fake website. Experts say the only real way to prevent these kinds of attacks is with improved training for staff and better cybersecurity protocols.
Correction
This is a corrected article. A previous version incorrectly stated the Confederation Centre did not pay the attackers a ransom.
CTVNews.ca Top Stories
What can you do to help mitigate shortages of fever and pain relievers?
Pharmacists and health care professionals are asking the public to only buy what they need and to be up to date on all their essential immunization shots to help with Tylenol, Advil shortages.

Long COVID risk extends two years after infection. Here's how to assess your risk
A new study has found an increased risk of certain long COVID-19 symptoms up to two years after an original infection.
Vatican shelves sexual assault probe into Cardinal Marc Ouellet
There is not enough evidence to open a formal church investigation into sexual assault allegations against Quebec Cardinal Marc Ouellet, Pope Francis said Thursday. The pontiff issued his statement through Matteo Bruni, director of the Holy See press office.
Closed-door national security committee of parliamentarians reviewing spyware use
Parliament's top-secret national security committee is launching a review into federal agencies' ability to intercept private communications, on the heels of the RCMP revealing it has been using spyware as part of major investigations, for decades.
Advocates say use of NDAs should be banned in sexual misconduct settlements
In the wake of the Hockey Canada scandal, some advocates are calling for the use of non-disclosure agreements to be banned or restricted in settlement agreements in cases involving abuse.
BREAKING | Trump Organization CFO pleads guilty in tax evasion case
A top executive at former U.S. President Donald Trump's family business pleaded guilty Thursday to evading taxes in a deal with prosecutors that could potentially make him a star witness against the company at a trial this fall.
Majority of people with Omicron don't know they have it: study
A new study has found that more than half of people infected with the Omicron variant of COVID-19 were unaware they had it. Undiagnosed infections could be the reason why the variant spread so rapidly, according to researchers.
Canada-wide shortage of liquid Children's Tylenol now also impacting chewables
A nationwide shortage of liquid Children’s Tylenol is also impacting generic chewables, with Quebec-based Laboratoire Riva reporting a shortage due to rising demand.
High-level talks in Ukraine yield little reported progress
Turkey's leader and the UN chief met in Ukraine with President Volodymr Zelenskyy on Thursday in a high-powered bid to ratchet down a war raging for nearly six months. But little immediate progress was reported.