Royal Canadian Mounted Police opened criminal probe into network cyberattack

Organization
Royal Canadian Mounted Police (RCMP)
Exploit
Hacking
Industry
Law Enforcement

The Royal Canadian Mounted Police confirmed on February 23, 2024 that its networks had been targeted in what it described as a cyber event, and said it had opened a criminal investigation alongside a separate cybersecurity review.

In its statement the force said a breach of that magnitude was alarming, but that there was no impact on RCMP operations and no known threat to the safety and security of Canadians. It added that it had no indication foreign police or intelligence partners were affected. The RCMP worked with Shared Services Canada, the Communications Security Establishment's Canadian Centre for Cyber Security and other federal partners to establish the scope of the intrusion, and notified the Office of the Privacy Commissioner of Canada.

The force declined to describe the nature of the attack, who was behind it or how access was gained, citing the active investigations. Its public website was also unreachable over the following weekend, but the RCMP said that outage was unrelated to the cyber event and was caused by high traffic on servers managed by Shared Services Canada. The site was restored by February 26.

Commissioner Mike Duheme said on February 27, 2024 that there was no evidence to date that data had been extracted from RCMP systems, calling that assessment good news while noting the work was continuing. The incident followed a January 2024 compromise at Global Affairs Canada and a 2023 breach at federal relocation contractors that exposed RCMP personnel records.

Sources