Breaking News: CFIB confirms data up for sale was stolen from the association

Share post:

An association representing Canadian small and medium-sized businesses has acknowledged someone recently stole and put up for sale a database of its prospects.

Dan Kelly, chief executive officer of the Canadian Federation of Independent Business, said Thursday the database is “mostly old information’ and not the main database of the estimated 97,000 members of the association.

Still, according to the posting on a criminal marketplace, the database has fields for names, street addresses, email addresses and mobile phone numbers — enough information for a phishing campaign. Kelly didn’t say how many names were in the stolen database.

Kelly said the federation didn’t know about the data leak until it was contacted by IT World Canada on Thursday morning. We were tipped off about the database being offered on a criminal marketplace by a cybersecurity researcher who spotted it.

The posting lists a date of 29/12/2022, suggesting the file was stolen on that date. The posting says the data format is CSV and the number of records is 972,235.

“It does look like its prospect data, not membership data,” Kelly said in an interview. “We’re not sure of the exact nature of it … so we’re doing a full investigation.”

The database appears to be a list of leads compiled for federation sales staff when they go door-knocking to sell memberships, he said. “It’s mostly old information,” he said, “very basic information that anybody could find by doing a Google search.”

It is “mostly information that any leads list of businesses that would have. Their information for the most part is public … It’s mostly stuff  that we’ve either collected ourselves in the past or perhaps from purchased lists of leads from businesses.”

Some of the businesses in the database may no longer be around, he added.

“We’re doing a further investigation just to make sure there isn’t anything [personal] in there that would worry anyone.”

It isn’t clear how the data was copied. The file was apparently held in a Microsoft Power BI database. “We think we have [now] closed all loopholes” in the application, Kelly said.

In December, the federation launched an online cybersecurity training program aimed at Canadian small and medium businesses.

The post Breaking News: CFIB confirms data up for sale was stolen from the association first appeared on IT World Canada.
Howard Solomon
Howard Solomon
Currently a freelance writer, I'm the former editor of and Computing Canada. An IT journalist since 1997, I've written for several of ITWC's sister publications including and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.


Related articles

Microsoft announces enhanced security feature for OneNote

Microsoft has released further information on the increased security measures it is deploying for OneNote in order to...

Russian hacker group steals Emails of NATO officials and diplomats

Since February 2023, a Russian hacking gang known as TA473 or 'Winter Vivern' has targeted unpatched Zimbra endpoints...

Canadian cybersecurity accelerator counts its accomplishments

A Canadian university-associated business accelerator for helping early-stage cybersecurity companies says its first two years of operation have been more than satisfactory. The Rogers Cybersecure Catalyst Accelerator has had “an incredible impact” on Canadian cybersecurity entrepreneurs and founders, executive director Charles Finlay said this week in the first report on the program’s progress. Despite having

Crackdown on ransomware gangs yet to show an impact: OpenText

In its annual cybersecurity report OpenText also looked at malware, phishing and infec

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways