Cyberattack hits vaccine records for thousands of Durham Region children: CTV News investigation
The personal information of more than three thousand children in daycares throughout Durham Region was stolen in a cyberattack early this year that CTV News Toronto has learned is larger than previously known.
That data from some 80 daycares, which also included the detailed vaccination records of some 200 children, was recently discovered on a website with ties to a Ukrainian group believed to be involved in ransomware attacks that was raided by police in June.
“That it’s out there for anybody to see is a little jarring,” Chris Perera said after learned his two-year-old child’s vaccine record was among the files that had been taken.
He said he had been warned in general by Durham Region that his data may have been affected, but he wished they had been more specific so that he would be able to better respond.
“When you get a letter from the region saying your information has been leaked, your head is going so many different ways, I wish they could have said specifically what’s out there,” he said.
Records seem to indicate that the personal information of some 3200 children and their families were taken as part of a file transfer that appears to be related to the uploading of the children’s vaccination status to the region’s health department.
Some day cares have been told that they are to cease sending that detailed vaccination information for now.
Nadine Koch, a supervisor at Kindertots Child Care Centre in Ajax, said her daycare has taken on keeping track of vaccination records by themselves.
“We’re just handling it on our own because we haven’t been told when to submit it. It’s been put on the back burner,” she said.
Koch said the region had informed them that they were among the daycares affected in April, the month after the breach was first discovered.
The breach appears to be related to the Accellion file transfer system, Brett Callow a threat analyst with Emsisoft told CTV News Toronto.
“That data somehow ended up in the hands of a group called CLOP,” he said.
The Ukrainian police said in a statement on their website they believe CLOP is behind attacks from South Korea to the United States, pointing to attacks in 2021 on the personal data and financial reports of Stanford University Medical School, the University of Maryland, and the University of California.
News of the arrests was sure to disrupt the group to some extent, but the group’s presence continues online, he said.
The Accellion software has been fixed, he said.
Durham Region has said it took “prompt steps” to contain the incident, which it said was caused by a vulnerability in a third party software.
“We have stopped using the third party software involved,” the region has said.
Perera said he is not as bothered about the information being online as he might be in another circumstance, as the vaccination data of his two-year-old isn’t going to help online predatorsin further attacks, including attempts at identity theft.
But he said it’s important that the region’s computers are secure.
"Cybersecurity needs to be a priority, especially when it’s an infrastructure that communicates such specific information."
CTVNews.ca Top Stories
Spectacular aurora light show to be seen across Canada Friday night
A rare and severe solar storm is expected to bring spectacular displays of the northern lights, also known as aurora borealis, across much of Canada and parts of the United States on Friday night.
Which Canadian cities have the highest and lowest grocery prices?
Where you live plays a big factor in what you pay at the grocery store. And while it's no secret the same item may have a different price depending on the store, city or province, we wanted to see just how big the differences are, and why.
McGill University seeks emergency injunction to dismantle pro-Palestinian encampment
McGill University has filed a request for an injunction to have the pro-Palestinian encampment removed from its campus.
Swarm of 20,000 bees gather around woman’s car west of Toronto
A swarm of roughly 20,000 bees gathered around a woman’s car in the parking lot of Burlington Centre.
U.S. says Israel's use of U.S. arms likely violated international law, but evidence is incomplete
The Biden administration said Israel's use of U.S.-provided weapons in Gaza likely violated international humanitarian law but wartime conditions prevented U.S. officials from determining that for certain in specific airstrikes.
Barron Trump declines to serve as an RNC delegate
Former U.S. President Donald Trump's youngest son, Barron Trump, has declined to serve as a delegate at this summer’s Republican National Convention, according to a senior Trump campaign adviser and a statement from Melania Trump's office.
Mother assaulted by stranger while breastfeeding baby in her car: Vancouver police
A person was arrested in East Vancouver Thursday after allegedly entering a car while a mother was breastfeeding her four-month-old boy.
'We have laws': Premier Smith says police action justified in Calgary
The actions, including the decision to use non-lethal force, to disperse pro-Palestinian protesters from the University of Calgary campus were justified, Alberta Premier Danielle Smith said Friday.
'State or state-sponsored actor' believed to be behind B.C. government hacks
The head of British Columbia’s civil service has revealed that a “state or state-sponsored actor” is behind multiple cyber-security incidents against provincial government networks.