Nova Scotia estimates up to 100,000 people affected by online security breach
As many as 100,000 Nova Scotians may have had sensitive personal information stolen in a global privacy breach affecting a file transfer system used by the provincial government, officials confirmed Tuesday.
Cybersecurity and Digital Solutions Minister Colton LeBlanc said a government investigation indicates social insurance numbers, addresses and banking information of current employees of the public service, as well as those at Nova Scotia Health and the IWK hospital, were taken.
LeBlanc says some information may also have been stolen from former public service and health authority employees. He said the information was shared through the MOVEit file transfer service, which the province uses to transfer employee payroll information.
"The investigation remains underway so there is the potential for this number to go up or to go down," the minister said. "I know this is an alarming situation, but rest assured we are working hard to solve this quickly and efficiently."
LeBlanc said the province is working to contact those affected and will be offering them a free credit monitoring service. "But when we are talking 100,000 Nova Scotians, that's going to be a challenge," added LeBlanc, who pointed out some people's contact information may have changed over the years. He also urged current and former employees to look for suspicious transactions and to contact their banks.
The department's deputy minister, Natasha Clarke, said that at this point there is no indication that any of the information compromised came from members of the public who were not provincial employees.
MOVEit software is made by Massachusetts-based company Ipswitch and allows organizations to transfer files and data between employees, departments and customers. Parent company Progress Software confirmed a vulnerability in its software last week, saying the issue could lead to potential unauthorized access of users' systems and files.
The Nova Scotia government has said it was first informed of a critical vulnerability within its system on Thursday. The province took the service off-line and installed a security update before bringing it back online Friday, only to be told further investigation was needed. Cybersecurity experts were then called in on Saturday evening.
Clarke confirmed the investigation indicates that the data was stolen two days before the Nova Scotia government learned of the vulnerability. "So once we put the patching in place, there was no more nefarious activity that we were able to see," she said.
Microsoft Threat Intelligence has said in a tweet that the Lace Tempest hacking group, which is known for running the Clop extortion site, exploited that vulnerability.
LeBlanc would not confirm who had hacked into Nova Scotia's system, adding "I am not going to comment on interactions with criminals." But Clarke said the government "at this point in time" is not negotiating with the hackers.
"Now the focus is understanding the impact of the data that has been stolen, and we have not been asked for any ransom," she said.
The deputy minister said the government has been working with its internal security team as well as with outside experts, including an unnamed large private firm that the province has on retainer. Clarke said Nova Scotia is also working with the Canadian Centre for Cyber Security.
In an email, MOVEit said it disabled web access to protect customers and developed the security patch and gave it to customers within 48 hours of discovering the vulnerability.
"We are continuing to work with industry-leading cybersecurity experts to investigate the issue and ensure we take all appropriate response measures," the company said. "We have engaged with federal law enforcement and other agencies with respect to the vulnerability."
This report by The Canadian Press was first published June 6, 2023.
For more Nova Scotia news, visit our dedicated provincial page.
CTVNews.ca Top Stories

U.S. judge rules Donald Trump defrauded banks, insurers while building real estate empire
A U.S. judge ruled Tuesday that Donald Trump committed fraud for years while building the real estate empire that catapulted him to fame and the White House, and he ordered some of the former president's companies removed from his control and dissolved.
Anthony Rota resigns as House Speaker amid condemnation for inviting Nazi veteran to Parliament
Anthony Rota has resigned from his prestigious position as Speaker of the House of Commons over his invitation to, and the House's subsequent recognition of, a man who fought for a Nazi unit during the Second World War. Now, Prime Minister Justin Trudeau is facing calls to apologize, and investigate.
Hollywood writers strike declared over after boards vote to approve contract with studios
Leaders of the screenwriters union declared their nearly five-month-old strike over Tuesday after board members approved a contract agreement with studios, bringing Hollywood at least partly back from a historic halt in production.
Five workers picketing in UAW strike hit by vehicle outside Flint-area plant
About five people picketing in the United Auto Workers strike outside a Flint-area General Motors plant suffered minor injuries Tuesday when a vehicle leaving the plant struck them, police said.
ER doctor challenging 'toxic environment' in Ontario hospital after secret investigation based on unfounded murder allegation
After more than 30 years of caring for critically ill patients in emergency and intensive care, Dr. Scott Anderson is preparing to face off against the hospital where he works in London, Ont., in a case described as "unusual" by lawyers and potentially costly for Ontario taxpayers.
Canadian women's soccer team earns Olympic berth with win over Jamaica
The Canadian women's national soccer team has clinched a spot in the 2024 Paris Games after defeating Jamaica 4-1 on aggregate in Olympic qualifying.
Is broadband essential, like water or electricity? New net neutrality effort makes the case
Landmark net neutrality rules rescinded under former President Donald Trump could return under a new push by U.S. Federal Communications Commission chair Jessica Rosenworcel. The rules would reclassify broadband access as an essential service on par with other utilities like water or power.
Comedian Rob Schneider cancels trip to Canada after veteran who fought for Nazis honoured in Parliament
Comedian Rob Schneider says he has cancelled an upcoming visit to Canada in light of last week’s incident in which a Ukrainian veteran who fought with a Nazi unit in the Second World War was given a standing ovation in the House of Commons.
How reindeer on an Arctic island survived thousands of years through inbreeding
An eye-brow raising phenomenon may be behind the success of Svalbard reindeer, researchers say, according to a new study analyzing how the species used inbreeding to survive in the Arctic archipelago.