Email hack may have revealed personal information, B.C. city warns residents

Share post:

A British Columbia municipality is warning residents that some of their personal information may be in the hands of hackers after the compromise of the city’s email system.

Richmond, a city of about 231,000 in the greater Vancouver area, gave that warning last week after learning fraudulent emails were being sent in June from individuals claiming to be members of the municipality’s staff or the city-owned Gateway Theatre. This related to the discovery on June 7th of what the city calls “unusual and concerning activity in its information technology environment.”

“While the city is unable to ascertain the exact types of personal information impacted by the attack, we are proceeding on the premise that some users may have shared personal information in their email communications with the city or Gateway Theatre,” the municipality said in a statement on its website. “This could include facility and program participant information such as contact details and birth dates; permit and licence applicant information such as home addresses and telephone numbers; among other types of personal information which may be submitted by the public through the course of routine business.

“Because the fraudulent email messages may contain a fake PDF file attachment or a link to a website that may be used to spread malware to harm your device and/or computer network, residents are urged not to click on any attachments or links in suspect emails.”

All official city or Gateway Theatre communications will only come from an official @richmond.ca or @gatewaytheatre.com e-mail address, the statement emphasizes.

“There is no indication the attack accessed the city’s financial or human resources data, or any other enterprise systems or databases,” the statement adds. “City operations have not been impacted and business continues as normal.”

The attack has been reported to the RCMP and the Office of the Information and Privacy Commission of B.C..

Experts warn that attackers don’t have to break into an organization’s files servers to get valuable information. Sometimes customers include personal information in emails to organizations. In addition staff may send sensitive personal and corporate information to each other either in messages or attachments. Hackers may also take advantage of their access to an email system to send malicious email from an employee so it looks legitimate, or insert themselves into an email conversation to get information. For these reasons access to email systems have to be protected with multi-factor authentication, and, if necessary, encryption.

The post Email hack may have revealed personal information, B.C. city warns residents first appeared on IT World Canada.
Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for several of ITWC's sister publications including ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

SUBSCRIBE NOW

Related articles

Cyber Security Today, May 3, 2024 – North Korea exploits weak email DMARC settings, and the latest Verizon analysis of thousands of data breaches

This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure

Hashtag Trending for World Password Day, Thursday, May 2nd, 2024

Security firm Okta warns of an unprecendented password stuffing attack that is piggybacking on regular user’s mobile and...

Google Chrome’s new post-quantum cryptography causes connection issues

The latest update to Google Chrome, version 124, which integrates a new quantum-resistant encryption mechanism, has led to...

UK legislation bans weak passwords

Starting Monday, the UK will enforce new laws banning the sale of devices with weak default passwords such...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways