Toronto Public Library still trying to determine if cardholder data was stolen in cyberattack
The Toronto Public Library it is still working to determine the full impact of a crippling cyberattack that disabled the library’s website for months, including whether the personal data of cardholders was accessed.
In the final report to the library board on the Oct. 28 cyberattack, City Librarian Vickery Bowles confirmed that the full extent of the data breach is still under investigation.
- Download our app to get local alerts on your device
- Get the latest local updates right to your inbox
The library previously indicated that the personal information of employees, including social insurance numbers and copies of government-issued identification, was stolen during the incident. Further investigation revealed that some information involving dependents and family members of staff was also impacted.
“Although cardholder, volunteer, and donor databases were not affected, some data about these groups likely resided on the compromised file server,” the report notes.
“The larger e-discovery process to investigate whether customer, donor or volunteer data has been taken from the affected file server is underway and will take more time to complete.”
Bowles added that the library will “continue to be transparent” and will notify anyone else who may be affected.
A final accounting of the data breach will be sent to Ontario’s Information and Privacy Commissioner, the report noted.
According to the report, third-party experts tasked with conducting a forensic analysis on the cause of the cyberattack have concluded that the attackers “breached a vulnerability in an internet-facing server” before “exfiltrating and encrypting data from a file server.”
“TPL’s quick action to isolate the environment immediately on discovering the attack led to containment on October 29, 2023, reducing further potential exposure,” the report read.
'A disturbing reality'
The library, Bowles said, has addressed the situation by rebuilding its network and implementing a number of cybersecurity enhancements.
“The rise in data security and ransomware incidents affecting organizations dedicated to community wellbeing, including hospitals, school boards, and libraries like TPL, is a disturbing reality,” the report concluded.
A sign at a Toronto Public Library branch is seen in this undated file image. (CTV News Toronto)
“Public sector organizations are increasingly becoming targets, whether motivated by financial gain or sheer malice. In the case of public libraries, dedicated to equity, access to information, intellectual freedom, and openness for all, this represents an attack on the very essence of civil society.”
Toronto library users were not able to place holds on books, access their accounts, or use computers on site for months following the cyberattack.
The library’s website was partially restored on Jan. 29 and the rest of the site is expected to be back up and running by the end of February.
“Service restoration has been a complex and detailed process involving enterprise-wide discussions and analysis,” the report read.
“Staff have worked tirelessly to restore all services as quickly as possible.”
CTVNews.ca Top Stories
Bird flu, measles top 2025 concerns for Canada's chief public health officer
As we enter 2025, Dr. Theresa Tam has her eye on H5N1 bird flu, an emerging virus that had its first human case in Canada this year.
Azerbaijan observes day of mourning for air crash victims as speculation mount about its cause
Azerbaijan on Thursday observed a nationwide day of mourning for the victims of the plane crash that killed 38 people and left all 29 survivors injured as speculation mounted about a possible cause of the disaster that remained unknown.
Donald Trump says he urged Wayne Gretzky to run for prime minister in Christmas visit
U.S. president-elect Donald Trump says he told Canadian hockey legend Wayne Gretzky he should run for prime minister during a Christmas visit but adds that the athlete declined interest in politics.
Working Well: Returning to the office can disrupt life. Here are some tips to navigate the changes
Heading into 2025, thousands of workers face an unsettling reality: after years of working from the comfort of home, they must return to the office full-time for the first time since the coronavirus pandemic or look for new work.
Prayers and tears mark 20 years since the Indian Ocean tsunami that killed some 230,000 people
People gathered in prayer and visited mass graves in Indonesia’s Aceh province on Thursday to mark 20 years since the massive Indian Ocean tsunami hit the region in one of modern history’s worst natural disasters.
New York taxi driver hits 6 pedestrians, 3 taken to hospital, police say
A taxicab hit six pedestrians in midtown Manhattan on Wednesday, police said, with three people — including a 9-year-old boy — transported to hospitals for their injuries.
Historical mysteries solved by science in 2024
This year, scientists were able to pull back the curtain on mysteries surrounding figures across history, both known and unknown, to reveal more about their unique stories.
Thousands without power on Christmas as winds, rain continue in B.C. coastal areas
Thousands of people in British Columbia are without power on Christmas Day as ongoing rainfall and strong winds collapse power lines, disrupt travel and toss around holiday decorations.
Ho! Ho! HOLY that's cold! Montreal boogie boarder in Santa suit hits St. Lawrence waters
Montreal body surfer Carlos Hebert-Plante boogie boards all year round, and donned a Santa Claus suit to hit the water on Christmas Day in -14 degree Celsius weather.