Investigation reveals thousands had info exposed in P.E.I. arts centre data breach
The full impact of a data breach at Prince Edward Island’s largest arts centre is now clear. The results of a recently completed investigation show thousands of people had their personal information exposed.
The cyberattack was first reported by the Confederation Centre of the Arts in January. In February, officials confirmed it was a ransomware attack, which exposed some personal information held on the organization’s servers.
“A ransomware attack is where criminals will encrypt or scramble the data and systems of an organization preventing them from being able to access it or use it, essentially rendering it all useless,” said David Shipley, CEO of New Brunswick-based cybersecurity firm Beauceron. “Then they hold it for an extortion payment.”
The centre did pay a ransom to the attackers, but didn't disclose the amount paid.
The recently completed investigation into the breach found about 3,000 people were exposed, some just names and email addresses, but others had their date of birth and social insurance number exposed.
“The attack basically took down our entire IT infrastructure,” said Jodi Zver, Confederation Centre of the Arts’ chief financial officer. “We had to rebuild everything from the ground up, new servers, new everything. That took a very long time, and until we had that done we didn’t have access to the data that told us whose information was there.”
Officials say the affected people have been contacted, with the highest risk being offered credit monitoring and insurance.
This isn’t the first time something like this has happened in the region. The City of Saint John was hobbled after its information technology systems were targeted by a similar attack.
Experts say municipal governments and small non-profit organizations are easy targets.
“These organizations do not, generally, have IT teams and they certainly don’t have robust cybersecurity in place,” said Shipley. “So if you have the choice between going up against a global bank with a half a billion dollar security budget and few thousand eager cybersecurity professionals, or you can pick on the little kids.”
The Confederation Centre’s new system has improved backups and monitoring, as well as new information management policy.
“We’re not storing people’s personal information,” said Zver. “So if or when this happens again then we’ll be fine because we know the information wasn’t there for them to take.”
Officials say the box office and payroll system was not breached, so stored financial information should have remained secure.
The vast majority of successful cyberattacks are against people, not IT infrastructure. Attacks include getting members of an organization to click on a bad link or login to a fake website. Experts say the only real way to prevent these kinds of attacks is with improved training for staff and better cybersecurity protocols.
Correction
This is a corrected article. A previous version incorrectly stated the Confederation Centre did not pay the attackers a ransom.
CTVNews.ca Top Stories
Richard Perry, record producer behind 'You're So Vain' and other hits, dies at 82
Richard Perry, a hitmaking record producer with a flair for both standards and contemporary sounds whose many successes included Carly Simon’s 'You’re So Vain,' Rod Stewart’s 'The Great American Songbook' series and a Ringo Starr album featuring all four Beatles, died Tuesday. He was 82.
Hong Kong police issue arrest warrants and bounties for six activists including two Canadians
Hong Kong police on Tuesday announced a fresh round of arrest warrants for six activists based overseas, with bounties set at $1 million Hong Kong dollars for information leading to their arrests.
Read Trudeau's Christmas message
Prime Minister Justin Trudeau issued his Christmas message on Tuesday. Here is his message in full.
Stunning photos show lava erupting from Hawaii's Kilauea volcano
One of the world's most active volcanoes spewed lava into the air for a second straight day on Tuesday.
Indigenous family faced discrimination in North Bay, Ont., when they were kicked off transit bus
Ontario's Human Rights Tribunal has awarded members of an Indigenous family in North Bay $15,000 each after it ruled they were victims of discrimination.
What is flagpoling? A new ban on the practice is starting to take effect
Immigration measures announced as part of Canada's border response to president-elect Donald Trump's 25 per cent tariff threat are starting to be implemented, beginning with a ban on what's known as 'flagpoling.'
Dismiss Trump taunts, expert says after 'churlish' social media posts about Canada
U.S. president-elect Donald Trump and those in his corner continue to send out strong messages about Canada.
Heavy travel day starts with brief grounding of all American Airlines flights
American Airlines briefly grounded flights nationwide Tuesday because of a technical problem just as the Christmas travel season kicked into overdrive and winter weather threatened more potential problems for those planning to fly or drive.
King Charles III is set to focus on healthcare workers in his traditional Christmas message
King Charles III is expected to use his annual Christmas message to highlight health workers, at the end of a year in which both he and the Princess of Wales were diagnosed with cancer.