Cyberattack hits vaccine records for thousands of Durham Region children: CTV News investigation
The personal information of more than three thousand children in daycares throughout Durham Region was stolen in a cyberattack early this year that CTV News Toronto has learned is larger than previously known.
That data from some 80 daycares, which also included the detailed vaccination records of some 200 children, was recently discovered on a website with ties to a Ukrainian group believed to be involved in ransomware attacks that was raided by police in June.
“That it’s out there for anybody to see is a little jarring,” Chris Perera said after learned his two-year-old child’s vaccine record was among the files that had been taken.
He said he had been warned in general by Durham Region that his data may have been affected, but he wished they had been more specific so that he would be able to better respond.
“When you get a letter from the region saying your information has been leaked, your head is going so many different ways, I wish they could have said specifically what’s out there,” he said.
Records seem to indicate that the personal information of some 3200 children and their families were taken as part of a file transfer that appears to be related to the uploading of the children’s vaccination status to the region’s health department.
Some day cares have been told that they are to cease sending that detailed vaccination information for now.
Nadine Koch, a supervisor at Kindertots Child Care Centre in Ajax, said her daycare has taken on keeping track of vaccination records by themselves.
“We’re just handling it on our own because we haven’t been told when to submit it. It’s been put on the back burner,” she said.
Koch said the region had informed them that they were among the daycares affected in April, the month after the breach was first discovered.
The breach appears to be related to the Accellion file transfer system, Brett Callow a threat analyst with Emsisoft told CTV News Toronto.
“That data somehow ended up in the hands of a group called CLOP,” he said.
The Ukrainian police said in a statement on their website they believe CLOP is behind attacks from South Korea to the United States, pointing to attacks in 2021 on the personal data and financial reports of Stanford University Medical School, the University of Maryland, and the University of California.
News of the arrests was sure to disrupt the group to some extent, but the group’s presence continues online, he said.
The Accellion software has been fixed, he said.
Durham Region has said it took “prompt steps” to contain the incident, which it said was caused by a vulnerability in a third party software.
“We have stopped using the third party software involved,” the region has said.
Perera said he is not as bothered about the information being online as he might be in another circumstance, as the vaccination data of his two-year-old isn’t going to help online predatorsin further attacks, including attempts at identity theft.
But he said it’s important that the region’s computers are secure.
"Cybersecurity needs to be a priority, especially when it’s an infrastructure that communicates such specific information."
CTVNews.ca Top Stories
BREAKING Bob Cole, veteran CBC broadcaster and former voice of 'Hockey Night in Canada,' dead at 90
Bob Cole, legendary CBC broadcaster and former voice of Hockey Night in Canada, has died. He was 90.
Harvey Weinstein's 2020 rape conviction overturned by N.Y. appeals court
New York's highest court on Thursday overturned Harvey Weinstein's 2020 rape conviction, reversing a landmark ruling of the #MeToo era in determining the trial judge improperly allowed women to testify about allegations against the ex-movie mogul that weren't part of the case.
BREAKING Honda to get up to $5B in govt help for EV battery, assembly plants
Honda is set to build an electric vehicle battery plant next to its Alliston, Ont., assembly plant, which it is retooling to produce fully electric vehicles, all part of a $15-billion project that is expected to include up to $5 billion in public money.
MPP Sarah Jama asked to leave Ontario legislature for wearing keffiyeh
MPP Sarah Jama was asked to leave the Legislative Assembly of Ontario by House Speaker Ted Arnott on Thursday for wearing a keffiyeh, a garment that is banned at Queen’s Park.
CTE: Researchers believe widespread brain injury may contribute to veteran suicide rate
Researchers are working to better understand if some Canadian military veterans may be suffering from Chronic Traumatic Encephalopathy, also known as CTE -- a disorder previously found in the brains of professional football and hockey players after their death.
1 arrested in northern Alberta during public shelter order
Residents of John D'Or Prairie, a community on the Little Red River Cree Nation in northern Alberta, were told to take shelter Thursday morning during a police operation.
Secret $70M Lotto Max winners break their silence
During a special winner celebration near their hometown, Doug and Enid shared the story of how they discovered they were holding a Lotto Max ticket worth $70 million and how they kept this huge secret for so long.
Remains from a mother-daughter cold case were found nearly 24 years later, after a deathbed confession from the suspect
A West Virginia father is getting some sense of closure after authorities found the remains of his young daughter and her mother following a deathbed confession from the man believed to have fatally shot them nearly two decades ago.
New deep-water channel allows first ship to pass Key bridge wreckage in Baltimore
The first cargo ship passed through a newly opened deep-water channel in Baltimore on Thursday after being stuck in the harbor since the Francis Scott Key Bridge collapsed four weeks ago, halting most maritime traffic through the city's port.