Attackers say they have deleted data stolen from Ontario school board

Share post:

A northern Ontario Catholic school district says crooks who stole data in December claim they have since deleted the information from their storage.

In a statement this week, the Huron-Superior Catholic District School Board said the unnamed attackers stole “a significant number of files from a board file server.”

“They have informed us that they have since deleted the files, and we believe the risk of misuse is low, but we, nonetheless, are going to analyze the files that were stolen and determine who to notify.  Given the number of files, this will take some time, possibly months.”

According to the news site SooToday — which covers the Sault Ste. Marie area — the board was hit with the Royal strain of ransomware.

Stolen was information held on employees dating back to 2019, including social insurance numbers, date of birth information, compensation information, banking information, and (if applicable) garnishment information.  Affected employees will receive a notification letter within the next two weeks.

They will be offered two years of free credit monitoring service – a service that allows one to check for signs of identity fraud so protective action can be taken.

It isn’t clear why the attackers disposed of what they stole. The news site Elliot Lake Today says the board isn’t saying if it paid a ransom.

Some ransomware gangs have self-imposed policies forbidding attacks on certain organizations. The LockBit ransomware gang, for example, forbids affiliates from attacking critical infrastructure providers. Under its limits, affiliates can only attack for-profit schools and school boards. The rules allow affiliates to steal data from hospitals but forbid hospital data from being encrypted.

After Toronto’s Hospital for Sick Children was hit with the LockBit ransomware, a gang leader apologized, blaming an affiliate for violating its rules.

The post Attackers say they have deleted data stolen from Ontario school board first appeared on IT World Canada.

Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

SUBSCRIBE NOW

Related articles

Cyber Security Today, May 15, 2024 – Ebury botnet still exploits Linux servers, Microsoft, SAP and Apple issue security updates

The Ebury botnet continues to exploit Linux servers, Microsoft, SAP and Apple issue security updates, and more. Welcome to...

Employee errors still predominant cause of data breaches: Verizon Report

In the latest 2024 Verizon Data Breach Report (DBIR), it has been revealed that employee errors remain the...

Black Basta has compromised over 500 organizations globally:CISA

The Cybersecurity and Infrastructure Security Agency (CISA) along with the FBI reported that the Black Basta ransomware group...

Cyber Security Today, May 10, 2024 – Patches for F5’s Next Central Manager released, Dell discovers data theft covering millions, and more

Patches for F5's Next Central Manager are released, Dell discovers data theft covering millions of buyers, and more Welcome...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways