NoEscape claimed an 80GB theft from the US-Canada International Joint Commission
- Organization
- International Joint Commission
- Exploit
- Ransomware
- Industry
- Government
The International Joint Commission, the binational body created by the 1909 Boundary Waters Treaty to oversee lakes and rivers along the border between the United States and Canada, confirmed in September 2023 that it had suffered a cybersecurity incident.
The confirmation followed a posting on September 7 by NoEscape, a ransomware-as-a-service operation, which named the commission on its dark web leak site. The group claimed to have taken roughly 80 gigabytes of material, described as more than 50,000 confidential files drawn from commission offices in Washington, Ottawa and Windsor. Its inventory listed contracts and legal documents, personal information on employees and members, financial and insurance records, geological files and conflict of interest forms. NoEscape gave the commission ten days to pay but did not name a figure.
A commission spokesperson said only that the organization had experienced a cybersecurity incident and was working with relevant organizations to investigate and resolve the situation. The commission declined to discuss law enforcement involvement, any effect on its operations, or whether it was considering payment.
NoEscape emerged in May 2023 and had by then listed victims in several countries, among them a German bar association and a university in Hawaii. Researchers described the operation as a probable rebrand of the earlier Avaddon group and noted its use of double extortion, stealing data before encrypting files.