City of Toronto exposed Tridel's banking information, city officials say
The City of Toronto exposed developer Tridel’s banking information to the public, city officials confirmed.
Tridel discovered its financial information was posted on a city web page, and alerted city officials of the incident in April, City of Toronto Media Relations Manager Russell Baker told CTV News.
“The City immediately removed the information and an internal investigation is underway,” Baker said.
Michael Mestyan, Tridel’s Vice President of Development Planning, said the company’s account information for transferring funds to the city was posted on the city's Application Information Centre website, which provides information on all active Community Planning, Committee of Adjustment and Toronto Local Appeal Body applications.
The duration this data was exposed is unknown, Mestyan said. “We cancelled the account immediately and are currently not aware of any issues that stemmed from the incident.”
Data breaches have recently plagued institutions in Toronto. Just a day earlier, the Toronto District School Board launched an investigation into a suspected cyberattack. This came on the heels of the public library’s paralyzing, months-long cyberattack, followed by hackers targeting the Toronto Zoo.
However, this breach is different, CTV Technology Analyst Carmi Levy said.
“What separates this case is that this wasn't a criminal act. This was a negligent act. And it was an accidental exposure by the City of Toronto,” Levy said, pointing out the fact that data was posted on the city’s website, rather than on the dark web where criminal hackers sell stolen data.
“This is about as nightmarish a scenario as you can imagine because something like this should never happen,” he said.
The first failure was that private data was posted to the public, highlighting a “very significant weakness” in the city’s management of information posted online.
“Failure number two was the information was out there and the city was blindly unaware of it until the victim of this error notified them that it was out there,” Levy said.
Given that an investigation is underway, Levy acknowledged his interpretation could differ from the findings, but that his initial observation was that this was not an attack – it was a mistake.
While information on how a data breach of this nature could happen remains sparse, cybersecurity expert Terry Cutler said it sounds like an inside job.
“When cyber criminals get access to a financial database with banking information, they would usually leak the whole thing,” Cutler said. Typically, hackers expose data on the dark web or extort the company that’s been breached.
“They just want money,” he said. “Once that data is out there, scammers can start doing financial fraud against Tridel.”
Speaking to the frequency of public institutions falling victim to cyberattacks, Cutler said it points to the fact that criminals now know these organizations don’t have the money or resources to deal with cyber security.
“It makes them a prime target,” he said.
CTVNews.ca Top Stories
Trudeau calls violence in Montreal 'appalling' as NATO protest continues
Anti-NATO protesters gathered again in Montreal on Saturday to demand Canada withdraw from the alliance, a day after a demonstration organized by different groups resulted in arrests, burned cars and shattered windows.
7 suspects, including 13-year-old, charged following 'violent' home invasion north of Toronto
Seven teenage suspects, including a 13-year-old, have been arrested following a targeted and “violent” home invasion in Vaughan on Friday, police say.
These vascular risks are strongly associated with severe stroke, researchers say
Many risk factors can lead to a stroke, but the magnitude of risk from some of these conditions or behaviours may have a stronger association with severe stroke compared with mild stroke, according to a new study.
Widow of Chinese businessman who was executed for murder can sell her Vancouver house, court rules
A murder in China and a civil lawsuit in B.C. have been preventing the sale of multiple Vancouver homes, but one of them could soon hit the market after a court ruling.
Cher 'shocked' to discover her legal name when she applied to change it
Cher recalls a curious interlude from her rich and many-chaptered history in her new book 'Cher: The Memoir, Part One.'
Black bear killed in self-defence after attack on dog-walker in Maple Ridge, B.C.
A black bear has died following a brawl with a man on a trail in Maple Ridge, B.C.
Retiring? Here's how to switch from saving for your golden years to spending
The last paycheque from a decades-long career arrives next Friday and the nest egg you built during those working years will now turn into a main source of income. It can be a jarring switch from saving for retirement to spending in retirement.
Canadian neurosurgeons seek six patients for Musk's Neuralink brain study
Canadian neurosurgeons in partnership with Elon Musk's Neuralink have regulatory approval to recruit six patients with paralysis willing to have a thousand electrode contacts in their brains.
Police thought this gnome looked out of place. Then they tested it for drugs
During a recent narcotics investigation, Dutch police said they found a garden gnome made of approximately two kilograms of MDMA.