Get all your news in one place.
100’s of premium titles.
One app.
Start reading
TechRadar
TechRadar
Sead Fadilpašić

Canadian government confirms data breach, says sensitive data may have been leaked

X.

Two Canadian relocation firms were recently breached and sensitive data on their customers was stolen. One of the customers was the Canadian government, meaning personally identifiable data of government employees was exposed. 

A report from BleepingComputer claims Brookfield Global Relocation Services (BGRS) and SIRVA Worldwide Relocation & Moving Services were the two firms that were affected.

 These two firms held government-related information on their servers, including data from the Royal Canadian Mounted Police, Canadian Armed Forces, and the Government of Canada. The data dates back to 1999.


LockBit claims responsibility

At press time, the type of the stolen data is unknown, as well as a more precise of affected individuals. The early conclusion is that whoever used the relocation services since 1999 has had both personal and financial data stolen. We do know that the Canadian government was made aware of the incident on October 19, after which it notified the police and other relevant organizations.

"The Government of Canada is not waiting for the outcomes of this analysis and is taking a proactive, precautionary approach to support those potentially affected," the organization said in a statement published late last week. "Services such as credit monitoring or reissuing valid passports that may have been compromised will be provided to current and former members of the public service, RCMP, and the Canadian Armed Forces who have relocated with BGRS or SIRVA Canada during the last 24 years.”

At the same time, the LockBit ransomware group took responsibility for the attack on SIRVA, saying it stole 1.5TB of sensitive information. The group added that negotiations failed. 

"Sirva.com says that all their information worth only $1m. We have over 1.5TB of documents leaked + 3 full backups of CRM for branches (eu, na and au)," BleepingComputer cited LockBit’s message on its dark web site.

More from TechRadar Pro

Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.