Toronto Zoo discloses ransomware incident, employee records taken

Organization
Toronto Zoo
Exploit
Ransomware
Industry
Zoo

The Toronto Zoo said it detected a security incident on its network early on Friday, January 5, 2024, and announced it in a statement issued on Monday, January 8. The zoo described the event as a ransomware and cyber incident and said it was working with the City of Toronto's Chief Information Security Office, third-party cyber security experts and Toronto Police Services.

In that first statement the zoo said animal wellbeing, care and support systems had not been affected, that it would stay open to guests, and that online ticket sales and its website were operating normally. It also said it did not store credit card information on its own systems.

A follow-up statement on January 17 said early findings indicated that personal data belonging to current, former and retired employees going back to 1989 had been taken, including past earnings information, social insurance numbers, dates of birth, telephone numbers and home addresses. Global News reported that affected staff were offered two years of credit monitoring. The zoo said it was still assessing whether member, guest, donor and volunteer records were involved.

The Akira ransomware group listed the zoo on its leak site on January 25, 2024. In a final update issued in March 2025, the zoo said guest and membership records from 2000 to April 2023 were affected, including names, addresses, phone numbers, email addresses, and the last four digits and expiry dates of cards used between January 2022 and April 2023.

Sources