Global Affairs Canada breach exposed employee data through a compromised VPN
- Organization
- Global Affairs Canada
- Exploit
- Hacking
- Industry
- Government
Global Affairs Canada, the federal department responsible for the country's diplomacy, trade and consular services, said in late January 2024 that it was investigating a breach of the network its staff use for remote access.
The department detected malicious cyber activity on January 24, 2024 and immediately sealed off remote access to its systems nationwide. An internal review indicated the intrusion dated back to December 20, 2023, giving the attackers roughly a month inside the environment. A memo told employees that anyone who had connected remotely with a SIGNET laptop since that date should assume their information was exposed and should take precautions.
Global Affairs Canada confirmed unauthorized access to personal information of users, including employees. Reporting indicated the compromise reached the contents of two internal drives along with the emails, calendars and contacts of a number of staff. The virtual private network used to reach the department's Ottawa headquarters, which was managed by Shared Services Canada, was identified as the compromised system.
The department took the VPN and some other systems offline, told remote workers to stop teleworking, and instructed staff to change passwords and regenerate encryption keys. On-site connectivity continued to function normally. Global Affairs Canada worked with Shared Services Canada and the Canadian Centre for Cyber Security on the response and said it was contacting affected individuals with mitigation measures. It made no public attribution.