Major data breach at one of Canada's largest investment firms 'so dangerous'
A data breach of social insurance numbers (SIN) belonging to the clientele of one of Canada’s largest investment firms is “so dangerous,” according to a former high-level employee at the company.
Terry Beck was the Manager of Operations at Mackenzie Investments, and an employee at the company for nearly 20 years, up until he retired in 2019. When he left, he divested his investments.
Yet a couple weeks ago, he said he received a letter from the corporation explaining that his SIN was compromised in a data breach.
Mackenzie informed clients in a letter dated April 27 that a third-party vendor, InvestorCOM Inc., was compromised by a cyber security incident related to data transfer supplier GoAnywhere. Clients' account numbers, names, and addresses were also compromised, according to one of the letters, reviewed by CTV News Toronto.
“This is so dangerous,” Beck told CTV News Toronto. “It’s an opening of a door to a lot of places.”
To work in Canada or access government programs and benefits, a nine-digit number – known as a SIN – is assigned to an individual. It is “private” and “illegal” for anyone else to use, according to the federal government.
“It’s the gateway to the government,” Beck said.
He said that when he was manager of operations four years ago, SINs were not shared with third-party vendors and that the practice could lead to continued privacy breaches.
A spokesperson for Mackenzie later disputed this fact, telling CTV News Toronto it was not correct.
In a statement on Monday, a Mackenzie spokesperson explained the company now uses SINs to identify and provide notifications to clients.
“Companies may use SINs as an identifier for reasons such as consolidating investor holdings so that fees associated with their account are reduced,” a spokesperson said.
“They may also share a client’s SIN as a unique identifier to third parties such as a dealer, group plan sponsor, and third-party service providers."
Beck acknowledged the necessity of consolidating a client’s accounts, but he questioned why a random set of numbers couldn’t stand in as a unique identifier, instead of a highly sensitive form of government identification.
“It could rear its head at any time down the road,” Beck said.
In a statement issued following the ransomware attack, Mackenzie said it regrets the effects the breach has had on their clientele.
“Mackenzie takes privacy and data protection very seriously and we are committed to protecting the confidentiality of all personal information. We greatly regret any concern or inconvenience this incident may cause to our valued clients,” a company spokesperson said in the statement.
The spokesperson said there has been no evidence of data misuse at this point in time and that the company reported the incident to the federal privacy commissioner, in addition to provincial privacy commissions.
LONG WAITS FOR RESOURCES
Shelly Rae, a Toronto resident and Mackenzie investor of about three decades, said she was concerned when she received a letter in the mail explaining that her personal information had been exposed.
“When someone has your name, phone number, address and SIN, that’s a pretty significant breach,” she said. “They can go on to steal your identity.”
After being notified that her information had been compromised, she said she spent about 10 hours on the phone in an attempt to sign up with a TransUnion credit monitoring service that Mackenzie is offering to impacted customers.
A Mackenzie spokesperson said the company is experiencing "particularly high volumes" of calls, leading to long wait times for victims of the breach seeking resources.
They said they "sincerely apologize" for the delays.
“The TransUnion call centres are doing their best to address all client concerns as quickly as possible by enhancing service capacity to help manage call volumes. We are proactively working with TransUnion to manage the high volume of calls and appreciate people’s patience,” the spokesperson said.
Despite credit monitoring services offered, Beck said “there’s nothing you can do" to change the fact that your SIN number is out there. "It will always be out there," he said.
Mackenzie noted that it is monitoring a range of sources for exposed data and to date have found no evidence of misuse.
CTVNews.ca Top Stories
A 'tragedy that can't be measured': North Bay's forever chemical problem is also the rest of Canada's
For decades, North Bay, Ontario's water supply has harboured chemicals associated with liver and developmental issues, cancer and complications with pregnancy. It's far from the only city with that problem.
opinion How to use your credit card as a powerful wealth-building tool
Irresponsibly using a credit card can land you in financial trouble, but personal finance columnist Christopher Liew says when used properly, it can be a powerful wealth-building tool that can help grow your credit profile and create new opportunities.
Which Canadian cities have the highest and lowest grocery prices?
Where you live plays a big factor in what you pay at the grocery store. And while it's no secret the same item may have a different price depending on the store, city or province, we wanted to see just how big the differences are, and why.
Here's what 'the hinge' move is, how to do it correctly
When you're picking something up from the floor or bending over to tie your shoe laces, you're performing "the hinge move," according to movement trainers.
Dashcam video shows terrifying near-miss on two-lane northern Ontario highway
There were some scary moments for several people on a northern Ontario highway caught on video Thursday after a chain reaction following a truck fire.
Swarm of 20,000 bees gather around woman’s car west of Toronto
A swarm of roughly 20,000 bees gathered around a woman’s car in the parking lot of Burlington Centre.
Average hourly wage in Canada now $34.95: StatCan
Average hourly wages among Canadian employees rose to $34.95 on a year-over-year basis in April, a 4.7 per cent increase, according to a Statistics Canada report released Friday morning.
Trump heading to Jersey Shore to rally 'mega crowd' in weekend break from hush money trial
After a long week in court, Donald Trump is heading to the Jersey Shore. And his campaign says he'll be joined by "tens of thousands" of his friends.
Barron Trump declines to serve as an RNC delegate
Former U.S. President Donald Trump's youngest son, Barron Trump, has declined to serve as a delegate at this summer’s Republican National Convention, according to a senior Trump campaign adviser and a statement from Melania Trump's office.