BGRS and SIRVA Canada breach exposed decades of federal relocation files

Organization
Brookfield Global Relocation Services (BGRS)
Exploit
Ransomware
Industry
Relocation Services

Brookfield Global Relocation Services (BGRS) and SIRVA Canada, two contractors that handle relocations for the Government of Canada, were compromised in the autumn of 2023. The RCMP said Treasury Board Secretariat was notified of the unauthorized access on September 29, 2023, and that the National Cybercrime Coordination Centre confirmed on October 19 that the RCMP was affected. No public source gives a date for when the intrusion itself occurred. The Treasury Board of Canada Secretariat made the breach public on November 17, 2023.

The exposure covered current and former federal public service employees, members of the Canadian Armed Forces and RCMP personnel who used the two firms' relocation services at any point between 1999 and September 2023. Because the contracts stretch back more than two decades, the potentially affected population was large and difficult to enumerate quickly.

Officials said the information held by the companies could include names, contact details, financial information and passport information. The government did not publish a victim count while the assessment continued.

Ottawa offered up to a year of credit monitoring and said it would reissue passports for people whose documents may have been compromised. Affected individuals were contacted in waves as they were identified. The Treasury Board, the Canadian Centre for Cyber Security, the RCMP and the Office of the Privacy Commissioner were all engaged, and the privacy commissioner opened an investigation on November 23, 2023. According to The Record, the LockBit ransomware group claimed in October 2023 that it had attacked SIRVA.

Sources