City of Toronto confirms data theft through GoAnywhere file transfer vendor

Organization
City of Toronto
Exploit
Supply Chain Attack
Industry
Municipal Government

The City of Toronto confirmed on 23 March 2023 that data had been taken from it through a third party file transfer service, three days after becoming aware of possible unauthorised access.

The vendor used Fortra's GoAnywhere managed file transfer product, which the Clop ransomware group had been attacking through CVE-2023-0669, a remote code execution flaw affecting instances whose administrative console was reachable from the internet. Clop added Toronto to its leak site on the same day the city issued its statement, alongside the Virgin Red rewards programme.

A city spokesperson said the access was limited to files that could not be processed through the third party secure file transfer system, that the investigation was at an early stage, and that the city would notify and communicate with anyone whose information turned out to be affected. The city did not say at that point whether resident data was involved.

The Toronto disclosure came in the middle of a broad campaign. Clop claimed to have compromised more than 130 organisations through the GoAnywhere flaw and added 39 new victims to its leak site on 23 March, part of roughly 91 organisations it listed over the course of the month, among them Hitachi Energy, Rubrik, Saks Fifth Avenue and the UK's Pension Protection Fund.

Sources