A ransomware attack hit Toronto Public Library. Here’s what that means
The Toronto Public Library (TPL) has confirmed the cybersecurity breach that caused a 10-day outage was brought on by a ransomware attack.
In a statement Tuesday, TPL said the cyberattack continues to impact some of the library’s services, including, but not limited to, accessing its website, digital collections and online access to user accounts. Library branches are still open, but public computers and printing services are currently unavailable.
A spokesperson for the library said a report with the Toronto Police Service has been filed. In its public statement, TPL said it is also working with third-party cybersecurity experts to resolve the situation.
“There continues to be no evidence at this time that the personal information of our staff or customers has been compromised,” the library said in the updated statement.
The TPL noted it “will take a week or more” before everything is fully restored but anticipates some services will be brought back sooner.
Daniel Tsai, technology and business lecturer at the University of Toronto, said ransomware attacks are typically carried out in a couple of ways where either someone clicks on a link, or downloads software through an attachment, providing a “backdoor access” for the hackers to take control.
“It’s basically a malevolent code that gets embedded into your system,” Tsai said.
“I don’t know the extent of what exactly is happening at TPL, but if they said it’s ransomware, then that means somebody, likely an employee, downloaded something or an attachment and activated a file – an executable file – that somehow compromised the system and [has] given, basically, hackers the ability to encrypt it and prevent access to that information by the institution.”
WHY WOULD HACKERS TARGET TPL?
This ransomware attack is just the latest to hit the province in an apparent spike of cyberattacks.
Earlier this month, six Ontario hospitals and health-care institutions confirmed some of their patient and employee data had been stolen in the same manner. A portion of that data has since been posted online.
Back in February, Canada’s largest bookstore chain Indigo Books & Music saw its payment systems go offline and the personal information of some current and former employees compromised.
“First of all, they try to pick targets that they think are going to pay good money,” Tsai said.
“They like going after places that have repositories of data, so that’s banks and public institutions, hospitals. But they also like going after entities that have very poor security, or at least, weak security.”
From the perspective of a cyber attacker, Tsai said TPL would likely be considered “low-hanging fruit.”
“This is all part of a growing trend, and it’s only going to get worse,” Tsai said. “We’ve seen it with hospitals already here in Ontario. We saw it with Indigo Books, and now with TPL. This is only just the beginning.”
WHAT INFORMATION ARE HACKERS LOOKING FOR? WHAT COULD THEY DO WITH IT?
Tsai said hackers are looking for sensitive information, like banking, social insurance numbers or employee data. With this information, he said hackers can engage in identity or credit card fraud.
“It depends on how widespread the attack is. Presumably, they tried to go after all the information,” Tsai said. “Employee data seems to be a treasure trove.”
With Indigo Books, for example, the retailer said in March the criminals behind the attack intend to make some – or potentially all – of the stolen data available through the “dark web.”
With regards to the TPL, Tsai said he thinks employee data would be the ”bigger prize” with cyberattacks since their financial information is likely linked.
HOW CAN ESTABLISHMENTS PROTECT THEMSELVES FROM RANSOMWARE ATTACKS?
Basic cybersecurity practices can prevent most ransomware incidents, according to the Canadian Centre for Cyber Security. This can include simulating cyberattacks to determine weak spots and based off the audit’s result, implementing proper features to ensure cyber defences are in place, Tsai said.
The Communications Security Establishment’s Canadian Centre for Cyber Security and the Royal Canadian Mounted Police urge Canadian establishments to review their networks’ cyber security, and have provided advice and recommended IT actions that they can adopt to curb the threat of a ransomware attack.
CTVNews.ca Top Stories

'Big, dark canvas of despair': Rick Hansen speaks on how his mindset changed after being paralyzed
Rick Hansen's life changed the day he was told he'd never walk again, but instead of letting his disability stand in his way, he became an advocate for accessibility rights and a Paralympic Athlete. Here's how that happened.
Sandie Rinaldo: Rick Hansen marks the 50th anniversary of his life-changing accident by visiting the scene
Rick Hansen lost the use of his legs in a truck accident when he was just 15 years old, CTV National News anchor, Sandie Rinaldo interviewed him recently while visiting the place where his life changed irrevocably.
Israeli offensive shifts to crowded southern Gaza, driving up death toll despite evacuation orders
Israel pounded targets in the crowded southern half of the Gaza Strip on Saturday and ordered more neighborhoods designated for attack to evacuate, driving up the death toll even as the United States and others urged it to do more to protect Gaza civilians.
Protester critically injured after setting self on fire outside Israeli consulate in Atlanta
A protester was in critical condition Friday after setting themself on fire outside the Israeli consulate in Atlanta, authorities said. A security guard who tried to intervene was also injured.
Russia brings new charges against jailed Kremlin foe Navalny
Imprisoned opposition leader Alexei Navalny has been handed new charges by Russian prosecutors.
Gatineau, Que. Facebook Marketplace sellers using fake addresses to scam buyers
Residents of a Gatineau, Que. neighbourhood have been dealing with a string of strangers knocking at the doors of their homes looking to pick up their purchased products from Facebook Marketplace, but instead discovering they had been scammed.
Alleged Montreal-area 'Chinese police stations' planning to sue RCMP for $2.5 million
Two Chinese community centres in the Montreal area are planning to launch a $2.5 million defamation lawsuit against the RCMP and the Attorney General of Canada after being accused by the police force of hosting 'alleged Chinese police stations.'
Lawyer in Ali murder trial says 13-year-old B.C. victim was not an 'innocent'
Ibrahim Ali's lawyer says the 13-year-old girl he's accused of murdering in a British Columbia park wasn't the “innocent” depicted in a “rose-coloured” portrayal by the Crown at trial.
'I cry all the time': Nova Scotia couple returns after 40 days in Gaza
It has been five days since Palestinian-Canadian couple, Khalil and Nabila Manna, returned from visiting relatives in Gaza, but while the couple planned to visit for a short-period of time, the Israel-Hamas conflict left them stranded for 40 days