Cyberattack hits vaccine records for thousands of Durham Region children: CTV News investigation
The personal information of more than three thousand children in daycares throughout Durham Region was stolen in a cyberattack early this year that CTV News Toronto has learned is larger than previously known.
That data from some 80 daycares, which also included the detailed vaccination records of some 200 children, was recently discovered on a website with ties to a Ukrainian group believed to be involved in ransomware attacks that was raided by police in June.
“That it’s out there for anybody to see is a little jarring,” Chris Perera said after learned his two-year-old child’s vaccine record was among the files that had been taken.
He said he had been warned in general by Durham Region that his data may have been affected, but he wished they had been more specific so that he would be able to better respond.
“When you get a letter from the region saying your information has been leaked, your head is going so many different ways, I wish they could have said specifically what’s out there,” he said.
Records seem to indicate that the personal information of some 3200 children and their families were taken as part of a file transfer that appears to be related to the uploading of the children’s vaccination status to the region’s health department.
Some day cares have been told that they are to cease sending that detailed vaccination information for now.
Nadine Koch, a supervisor at Kindertots Child Care Centre in Ajax, said her daycare has taken on keeping track of vaccination records by themselves.
“We’re just handling it on our own because we haven’t been told when to submit it. It’s been put on the back burner,” she said.
Koch said the region had informed them that they were among the daycares affected in April, the month after the breach was first discovered.
The breach appears to be related to the Accellion file transfer system, Brett Callow a threat analyst with Emsisoft told CTV News Toronto.
“That data somehow ended up in the hands of a group called CLOP,” he said.
The Ukrainian police said in a statement on their website they believe CLOP is behind attacks from South Korea to the United States, pointing to attacks in 2021 on the personal data and financial reports of Stanford University Medical School, the University of Maryland, and the University of California.
News of the arrests was sure to disrupt the group to some extent, but the group’s presence continues online, he said.
The Accellion software has been fixed, he said.
Durham Region has said it took “prompt steps” to contain the incident, which it said was caused by a vulnerability in a third party software.
“We have stopped using the third party software involved,” the region has said.
Perera said he is not as bothered about the information being online as he might be in another circumstance, as the vaccination data of his two-year-old isn’t going to help online predatorsin further attacks, including attempts at identity theft.
But he said it’s important that the region’s computers are secure.
"Cybersecurity needs to be a priority, especially when it’s an infrastructure that communicates such specific information."
CTVNews.ca Top Stories
Young people 'tortured' if stolen vehicle operations fail, Montreal police tell MPs
One day after a Montreal police officer fired gunshots at a suspect in a stolen vehicle, senior officers were telling parliamentarians that organized crime groups are recruiting people as young as 15 in the city to steal cars so that they can be shipped overseas.
Mandisa, Grammy award-winning 'American Idol' alum, dead at 47
Soulful gospel artist Mandisa, a Grammy-winning singer who got her start as a contestant on 'American Idol' in 2006, has died, according to a statement on her verified social media. She was 47.
Man sets self on fire outside New York court where Trump trial underway
A man set himself on fire on Friday outside the New York courthouse where Donald Trump's historic hush-money trial was taking place as jury selection wrapped up, but officials said he did not appear to have been targeting Trump.
Sask. father found guilty of withholding daughter to prevent her from getting COVID-19 vaccine
Michael Gordon Jackson, a Saskatchewan man accused of abducting his daughter to prevent her from getting a COVID-19 vaccine, has been found guilty for contravention of a custody order.
She set out to find a husband in a year. Then she matched with a guy on a dating app on the other side of the world
Scottish comedian Samantha Hannah was working on a comedy show about finding a husband when Toby Hunter came into her life. What happened next surprised them both.
Shivering for health: The myths and truths of ice baths explained
In a climate of social media-endorsed wellness rituals, plunging into cold water has promised to aid muscle recovery, enhance mental health and support immune system function. But the evidence of such benefits sits on thin ice, according to researchers.
'It could be catastrophic': Woman says natural supplement contained hidden painkiller drug
A Manitoba woman thought she found a miracle natural supplement, but said a hidden ingredient wreaked havoc on her health.
Manitoba mom praises quick-thinking fire department for freeing daughter stuck in playground equipment
A Manitoba mother is praising firefighters for their quick work in helping her daughter who got stuck at a playground in Lorette, Man.
The Body Shop Canada explores sale as demand outpaces inventory: court filing
The Body Shop Canada is exploring a sale as it struggles to get its hands on enough inventory to keep up with "robust" sales after announcing it would file for creditor protection and close 33 stores.