Cyberattack hits vaccine records for thousands of Durham Region children: CTV News investigation
The personal information of more than three thousand children in daycares throughout Durham Region was stolen in a cyberattack early this year that CTV News Toronto has learned is larger than previously known.
That data from some 80 daycares, which also included the detailed vaccination records of some 200 children, was recently discovered on a website with ties to a Ukrainian group believed to be involved in ransomware attacks that was raided by police in June.
“That it’s out there for anybody to see is a little jarring,” Chris Perera said after learned his two-year-old child’s vaccine record was among the files that had been taken.
He said he had been warned in general by Durham Region that his data may have been affected, but he wished they had been more specific so that he would be able to better respond.
“When you get a letter from the region saying your information has been leaked, your head is going so many different ways, I wish they could have said specifically what’s out there,” he said.
Records seem to indicate that the personal information of some 3200 children and their families were taken as part of a file transfer that appears to be related to the uploading of the children’s vaccination status to the region’s health department.
Some day cares have been told that they are to cease sending that detailed vaccination information for now.
Nadine Koch, a supervisor at Kindertots Child Care Centre in Ajax, said her daycare has taken on keeping track of vaccination records by themselves.
“We’re just handling it on our own because we haven’t been told when to submit it. It’s been put on the back burner,” she said.
Koch said the region had informed them that they were among the daycares affected in April, the month after the breach was first discovered.
The breach appears to be related to the Accellion file transfer system, Brett Callow a threat analyst with Emsisoft told CTV News Toronto.
“That data somehow ended up in the hands of a group called CLOP,” he said.
The Ukrainian police said in a statement on their website they believe CLOP is behind attacks from South Korea to the United States, pointing to attacks in 2021 on the personal data and financial reports of Stanford University Medical School, the University of Maryland, and the University of California.
News of the arrests was sure to disrupt the group to some extent, but the group’s presence continues online, he said.
The Accellion software has been fixed, he said.
Durham Region has said it took “prompt steps” to contain the incident, which it said was caused by a vulnerability in a third party software.
“We have stopped using the third party software involved,” the region has said.
Perera said he is not as bothered about the information being online as he might be in another circumstance, as the vaccination data of his two-year-old isn’t going to help online predatorsin further attacks, including attempts at identity theft.
But he said it’s important that the region’s computers are secure.
"Cybersecurity needs to be a priority, especially when it’s an infrastructure that communicates such specific information."
CTVNews.ca Top Stories
Several flight attendants from Pakistan have gone missing after landing in Canada
Multiple flight attendants from Pakistan International Airlines have abandoned their jobs and are believed to have sought asylum in Canada in the past year and a half, a spokesperson for the government-owned airline says.
BREAKING Ottawa public school board, 3 Toronto-area school boards launch lawsuit against social media giants
The Ottawa-Carleton District School Board and three school boards in the Toronto-area have launched legal action against social media giants, accusing them of "disrupting students' fundamental right to education."
Rainfall warnings of up to 90 mm among weather alerts in effect for 7 provinces
Rainfall warnings of up to 90 millimetres, air quality advisories and other alerts have been issued for seven Canadian provinces, according to the latest forecasts.
Tipping is off the table at this Toronto restaurant
A Toronto restaurant introduced a surprising new rule that reduced the cost of a meal and raised the salaries of staff.
A Nigerian woman reviewed some tomato puree online. Now she faces jail
A Nigerian woman who wrote an online review of a can of tomato puree is facing imprisonment after its manufacturer accused her of making a “malicious allegation” that damaged its business.
Donald Trump assails judge and his daughter after gag order in N.Y. hush-money criminal case
Donald Trump lashed out Wednesday at the New York judge who put him under a gag order that bars him from commenting publicly about witnesses, prosecutors, court staff and jurors in his upcoming hush-money criminal trial.
A fight to protect the dignity of Michelangelo's David raises questions about freedom of expression
Michelangelo's David has been a towering figure in Italian culture since its completion in 1504. But in the current era of the quick buck, curators worry the marble statue's religious and political significance is being diminished.
Doctors visiting a Gaza hospital are stunned by the war's toll on Palestinian children
An international team of doctors visiting a hospital in central Gaza was prepared for the worst. But the gruesome impact Israel’s war against Hamas is having on Palestinian children still left them stunned.
China's latest EV is a 'connected' car from smart phone and electronics maker Xiaomi
Xiaomi, a well-known maker of smart consumer electronics in China, is joining the country's booming but crowded market for electric cars.