Inadequate security led to federal breach that compromised Canadians’ info: watchdog

Advertisement

Advertise with us

OTTAWA - Government departments lacked adequate protections to fend off a "sophisticated and co-ordinated" cyberattack that compromised the sensitive information of tens of thousands of Canadians, the federal privacy watchdog has found.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 15/02/2024 (945 days ago), so information in it may no longer be current.

OTTAWA – Government departments lacked adequate protections to fend off a “sophisticated and co-ordinated” cyberattack that compromised the sensitive information of tens of thousands of Canadians, the federal privacy watchdog has found.

In a report tabled Thursday, privacy commissioner Philippe Dufresne describes how the lapse at the Canada Revenue Agency and Employment and Social Development Canada in summer 2020 allowed hackers to fraudulently collect payments.

The report says the breach of financial, banking and employment data led to numerous cases of fraud and identity theft, including many illicit applications for COVID-19 emergency response benefits.

The federal privacy watchdog says two government departments lacked adequate protections to prevent a cyberbreach that compromised the sensitive information of tens of thousands of Canadians. Privacy Commissioner of Canada Philippe Dufresne delivers results of an investigation, at a press conference in Ottawa, on Thursday, Jan. 26, 2023. THE CANADIAN PRESS/Spencer Colby
The federal privacy watchdog says two government departments lacked adequate protections to prevent a cyberbreach that compromised the sensitive information of tens of thousands of Canadians. Privacy Commissioner of Canada Philippe Dufresne delivers results of an investigation, at a press conference in Ottawa, on Thursday, Jan. 26, 2023. THE CANADIAN PRESS/Spencer Colby

The investigation found the revenue and employment departments had underestimated the level of identity authentication needed for their online programs and services.

The commissioner also concluded the departments did not take the necessary steps to promptly detect and contain the breach.

Both organizations have agreed to implement recommendations aimed at ensuring efficient safeguards against attacks, rapid response to breaches and regular security assessments.

“Federal government departments and agencies are attractive targets for cyberattacks and must have robust safeguards to mitigate against breaches and protect the sensitive personal information and programs that they manage,” Dufresne said in a statement.

“If a breach does occur, it is crucial that organizations act promptly to remedy the situation and prevent further damage to those affected.”

The commissioner found that attackers used, among other things, the revenue agency’s sign-in portal and ESDC’s “GCKey” authentication service to get into their online services and access individuals’ accounts using stolen login information and passwords obtained during previous breaches.

Attackers used a technique known as credential stuffing, allowing them to access, modify and create new online accounts in these stolen identities to fraudulently redirect government benefit payments to other bank accounts, the report says.

It also notes challenges the commissioner faced in the form of “delayed and missing breach reports and accessing information from departments during the investigation.”

“Unnecessary delays can increase harms flowing from a breach and hinder the investigative process,” the report says.

In addition, the commissioner’s office is following up with the revenue agency on separate breaches regarding Canada Emergency Response Benefit fraud in 2020, which it learned about in the final stages of the initial investigation.

Preliminary information indicates 15,000 individuals may have been affected.

Notwithstanding these concerns, the office says it is encouraged by the commitment from both the revenue and employment departments to implement the recommendations.

“We will expect all government departments to consider the lessons from this report in reducing the probability of a future breach of this magnitude.”

This report by The Canadian Press was first published Feb. 15, 2024.

Report Error Submit a Tip

Canada

LOAD CANADA ARTICLES