Toronto Symphony Orchestra warns customer details compromised in ransomware attack
The Toronto Symphony Orchestra is warning its patrons that some of their personal information may have been compromised in a recent ransomware attack.
In an email sent out to patrons Monday afternoon, the TSO said that its email provider, WordFly, became aware of a "network disruption" on July 10.
“We have come to learn that WordFly was subject to a ransomware attack,” the TSO said in its email. “As part of the incident, the attacker exported customers’ information from the WordFly environment, including patron information that WordFly was handling on behalf of the TSO.”
A ransomware attack typically involves cybercriminals infiltrating the target’s computer systems and locking them down until a ransom is paid.
In this case, the attacker encrypted WordFly’s data and exported it several days later.
WordFly told the TSO that there is “no evidence” to suggest the data was misused or made publicly available.
“Further, WordFly’s understanding is that the data has now been deleted from the attacker’s possession,” the orchestra said.
The compromised information included names, email addresses, TSO patron IDs and other information such as donor level and survey responses, which could include demographic data like age, gender and ethnicity.
Payment and financial data were not compromised in the breach, the TSO said.
The TSO said that it has temporally partnered with another email provider, Mailchimp, in order to stay in touch with its patrons.
The organization said that it is informing patrons about the incident “out of an abundance of caution” and advised them to remain vigilant about suspicious emails or phone calls which might try to fraudulently obtain further information and to check accounts for unauthorized charges or transactions.
“Please accept our sincere apologies,” the orchestra said. “We take the security of our data and systems very seriously, and we value the trust that you place in us.”
WordFly has been down for two weeks since the breach was discovered. On a website set up to provide updates to customers, the vendor said that it has “retained experts” to restore its systems.
“It is our understanding that as of the evening of July 15, 2022, the data was deleted from the bad actor’s possession,” the company said in a statement a week ago. “We have no evidence to suggest, before the bad actor deleted the data, that the data was leaked or disseminated elsewhere. We also have no evidence to suggest that any of this information has been, or will be, misused.”
CTVNews.ca Top Stories
Biden pardons his son Hunter despite previous pledges not to
U.S. President Joe Biden pardoned his son, Hunter, on Sunday night, sparing the younger Biden a possible prison sentence for federal felony gun and tax convictions and reversing his past promises not to use the extraordinary powers of the presidency for the benefit of his family.
Canada Post presents union with 'framework' to reach deal as strike continues
Canada Post has presented the union representing some 55,000 striking postal workers with a framework to reach negotiated agreements, the corporation said.
'Devastating': Missing Surrey, B.C. teen found dead, family says
The family of a missing 18-year-old, who was last seen in Surrey over a month ago, says there has been a tragic end to the search.
opinion Are you overpaying for subscriptions? It's time for an audit
From streaming platforms and apps to gym memberships and meal kits, subscriptions are convenient, but it's easy to overlook how much you're spending. Personal finance contributor Christopher Liew offers tips on how to audit your subscriptions to save money.
Elton John says he has lost his eyesight and struggles to see his new stage musical
Elton John says he struggled to watch his new musical because he has lost his eyesight after contracting an infection.
PM Trudeau 'surprised' provinces unanimous on accelerated defence spending: Ford
Ontario Premier Doug Ford says his fellow provincial leaders are united in pushing for Canada to meet its NATO defence spending targets ahead of schedule, and that Prime Minister Justin Trudeau was 'surprised' to hear it.
Muskoka reacts to major snowfall, Highway 11 still closed
From road closures, power outages, weather declarations and nonstop shoveling, Muskoka residents were faced with nearly a metre of persistent snowfall this weekend.
Stellantis CEO resigns as carmaker sales continue to slump
Stellantis CEO Carlos Tavares is stepping down after nearly four years in the top spot of the automaker, which owns car brands like Jeep, Citroën and Ram, amid an ongoing struggle with slumping sales.
56 people killed in stampede following clashes at a Guinea soccer match, authorities say
Fifty-six people were killed and several injured in a stampede at a soccer stadium in southern Guinea, following clashes between fans, Guinea's government said Monday.