Hackers leak police takedown video, medical records in Durham Region breach: CTV News Toronto investigation
A CTV News Toronto investigation has discovered that a data breach at the Durham Regional government is much larger than already known, including medical reports, complaints about medical treatment, and potential evidence in a criminal case.
That data, including security camera video that shows a man’s arrest on a Durham Regional Transit bus by Toronto Police officers, is the kind of thing that should have been encrypted to protect privacy in case of a hostile cyberattack, says Ontario’s former information and privacy commissioner, Ann Cavoukian.
“It is astonishing to me,” Cavoukian said in an interview, pointing to an order she made back in 2010 to Durham region to encrypt some portable medical data after an employee lost a USB stick.
“The value of encryption is enormous. In this case, when you’re talking about someone hacking, it doesn’t matter what the cause of the interception is, if you encrypt the data, especially sensitive health data, then you’ve protected it from the beginning,”
Durham Region has said they were a victim of a cybersecurity incident, which occurred through a third-party software provider. Several gigabytes of its data was posted online by a group called CLOP. Members of that group were arrested this summer in Ukraine.
At the time, police there said the group’s worldwide ransomware attacks included several Canadian companies, costing its victims around $500 million.
The region of Durham was just one of those victims. At first they announced their breach involved the personal information of tens of thousands of public school students. CTV News Toronto revealed in August it also included thousands of children in day care, including their vaccination statuses.
The new video shows the bus travelling at Ellesmere and Meadowvale at about 5:10 p.m. on December 5.
A man gets on and sits in the seats to the rear of the driver. A short time after that, police cars surround the bus, and officers board to subdue the man.
“Do you have any weapons on you, bud?” one officer asks.
“No, not today,” he responds.
The man is taken off the bus and eventually would be charged with attempted murder, aggravated assault with a weapon, possession of a weapon, carrying a concealed weapon, theft, assault, and disobeying a court order.
His lawyer didn’t wish to comment to CTV News Toronto.
Toronto Police Service confirmed several details of the incident, and expressed concern that this video was public before the man’s trial.
“As this case is before the courts, any video of the arrest is considered evidence,” a TPS spokesperson said.
The CLOP data dump also includes applications for government assistance, medical reports, and complaints about medical treatment.
Some people whose names were mentioned in these documents told CTV News Toronto that Durham Region had contacted them; others said they had no idea -- including the driver of the Durham Regional Transit bus.
“The incident impacted a small portion of the overall data managed by the region… working with third-party experts, we have completed our investigation into this incident and taken actions to strengthen our cybersecurity safeguards,” the region said in a statement.
Background
Durham Region was a victim of cybersecurity incident, which occurred through a third-party software provider. This software is no longer used by the Region.
The incident impacted a small portion of the overall data managed by the Region. We have directly notified all individuals who we identified may have been affected and invited them to reach out for additional information. We also posted public statements and FAQs at www.durham.ca/CyberSecurity. It is important to note that there is no evidence of personal information listed within notification letters being compromised or misused.
Working with third-party experts, we have completed our investigation into this incident and taken actions to strengthen our cybersecurity safeguards. We have reported this incident to the regulator and will work to implement any recommendations they provide.
We have provided additional information to residents at www.durham.ca/CyberSecurity. We are committed to protecting the privacy of residents. We are sorry for the inconvenience this may have caused.
CTVNews.ca Top Stories
BREAKING Honda to get up to $5B in govt help for EV battery, assembly plants
Honda is set to build an electric vehicle battery plant next to its Alliston, Ont., assembly plant, which it is retooling to produce fully electric vehicles, all part of a $15-billion project that is expected to include up to $5 billion in public money.
BREAKING New York appeals court overturns Harvey Weinstein's 2020 rape conviction from landmark #MeToo trial
New York’s highest court on Thursday overturned Harvey Weinstein’s 2020 rape conviction, finding the judge at the landmark #MeToo trial prejudiced the ex-movie mogul with improper rulings, including a decision to let women testify about allegations that weren’t part of the case.
Residents of northern Alberta First Nation told to shelter in place
Residents of John D'Or Prairie, a community on the Little Red River Cree Nation in northern Alberta, were told to take shelter Thursday morning during a police operation.
Monthly earnings rise, payroll employment falls: jobs report
The number of vacant jobs in Canada increased in February, while monthly payroll employment decreased in food services, manufacturing, and retail trade, among other sectors.
Doctors say capital gains tax changes will jeopardize their retirement. Is that true?
The Canadian Medical Association asserts the Liberals' proposed changes to capital gains taxation will put doctors' retirement savings in jeopardy, but some financial experts insist incorporated professionals are not as doomed as they say they are.
Secret $70M Lotto Max winners break their silence
During a special winner celebration near their hometown, Doug and Enid shared the story of how they discovered they were holding a Lotto Max ticket worth $70 million and how they kept this huge secret for so long.
Remains from a mother-daughter cold case were found nearly 24 years later, after a deathbed confession from the suspect
A West Virginia father is getting some sense of closure after authorities found the remains of his young daughter and her mother following a deathbed confession from the man believed to have fatally shot them nearly two decades ago.
Something in the water? Canadian family latest to spot elusive 'Loch Ness Monster'
For centuries, people have wondered what, if anything, might be lurking beneath the surface of Loch Ness in Scotland. When Canadian couple Parry Malm and Shannon Wiseman visited the Scottish highlands earlier this month with their two children, they didn’t expect to become part of the mystery.
Metro Vancouver mayors call for serial killer Robert Pickton to be denied parole
A dozen mayors from around Metro Vancouver say federal Attorney General and Justice Minister Arif Virani should deny parole for notorious B.C. serial killer Robert Pickton, and reassess the parole and sentencing system for 'prolific offenders and mass murderers.'