Sobeys admits to data breach in fall 2022, alerts customers
It was a cyber-security incident that made headlines across the country late last year. Although the company involved waited until now to confirm it.
The Maritime-based Empire Co. – parent company of Sobeys – acknowledges customers and employees past and present are receiving letters saying their personal information may have been compromised.
Bill Zebedee received his letter in the mailbox late last week from Medical Health Care Services Inc. (MHCSI) -- the company that provides group benefit plans and works with pharmacies, including Sobeys and Lawtons.
Zebedee said when he first read the letter he was confused.
“I was very surprised because I never heard of the company. I contacted them to confirm it was real,” he said.
The letters informed recipients that an unnamed third party gained access to Sobeys servers on Nov. 1, 2022.
Experts say more letters may be sent out.
“This is one particular sub-company within the overall Empire Co. group of companies who may be affected, so we may see different kinds of these letters arriving,” said cyber security expert David Shipley.
The company was heavily criticized for its lengthy silence on the issue for weeks. Business professor Ed McHugh said the letters come as no surprise.
“This breach was large when it happened because they couldn’t accept gift cards at Sobeys for a while and Lawtons [also] had some issues, so we knew the breach was significant and Sobeys had been very quiet about this matter," adds McHugh.
In an email to CTV News, Sobeys said, “With the help of external experts, we have investigated how an unauthorized third party gained access to some of our servers and systems. The process to identify what data has been impacted has been extremely complex, and we’ve now reached a point where we can notify those who were potentially impacted.”
The retail giant also said, “We have seen no evidence that personal data was accessed or removed from our servers; however, out of an abundance of caution, we have sent notifications to those who could have been potentially impacted and in compliance with our regulatory obligations. IT security is and has always been a priority for us. Trust and transparency matter deeply and we regret that this event occurred.”
While the letter shares how the information could potentially be used by hackers, Shipley said clearer communication should have been provided much sooner.
“They should have had a media release in an actual press conference and say we’ve started the process of notifying people, so that way we could have had some understanding of who was going to get what notification so people could actually trust them,” he said.
Sobeys has not been alone in dealing with cyber security issues. In recent years, hackers have targeted various businesses and organizations. McHugh said in this case, it is best to be cautious.
“Be very vigilant in phone calls and emails and if something sounds too good to be true, it probably is,” he said.
As for now, it’s unclear how many letters have been sent out, however, we have learned employees are being offered a one-year subscription to a credit monitoring service.
Letters also urge recipients to keep an eye out for possible phishing attempts and avoiding clicking links or downloading attachments from suspicious emails.
CTVNews.ca Top Stories
LIVE AT 11 EST Trudeau to announce temporary GST relief on select items heading into holidays
Prime Minister Justin Trudeau will announce a two-month GST relief on select items heading into holidays to address affordability issues, sources confirm to CTV News.
'Ding-dong-ditch' prank leads to kidnapping, assault charges for Que. couple
A Saint-Sauveur couple was back in court on Wednesday, accused of attacking a teenager over a prank.
Joly says next U.S. ambassador Hoekstra will help advance 'shared priorities'
Foreign Affairs Minister Melanie Joly is welcoming president-elect Donald Trump's pick for the next U.S. ambassador in Ottawa.
Estate sale Emily Carr painting bought for US$50 nets C$290,000 at Toronto auction
An Emily Carr painting that sold for US$50 at an estate sale has fetched C$290,000 at a Toronto auction.
Parole board 'working' to have Bernardo victims' families attend hearing in-person
The Parole Board of Canada says it is now working to allow victims' families to attend Paul Bernardo's parole hearing and deliver their victim impact statements in person.
Police report reveals assault allegations against American TV presenter
A woman told police that she was sexually assaulted in 2017 by Pete Hegseth after he took her phone, blocked the door to a California hotel room and refused to let her leave, according to a detailed investigative report made public late Wednesday.
Border agency detained dozens of 'forced labour' cargo shipments. Now it's being sued
Canada's border agency says it has detained about 50 shipments of cargo over suspicions they were products of forced labour under rules introduced in 2020 — but only one was eventually determined to be in breach of the ban.
Smuggler arrested with 300 tarantulas strapped to his body
Police in Peru have arrested a man caught trying to leave the country with 320 tarantulas, 110 centipedes and nine bullet ants strapped to his body.
Ontario man agrees to remove backyard hockey rink
A Markham hockey buff who built a massive backyard ice rink without permissions or permits has reluctantly agreed to remove the sprawling surface, following a years-long dispute with the city and his neighbours.