Employee banking information stolen from Tennis Canada in cyber incident: Report

Share post:

Tennis Canada, a non-profit that oversees professional events and junior training programs, has acknowledged being hit by a cyber event in June resulting in “precautionary identity theft protection and credit monitoring to all of our employees.”

In a statement this week, the association said that after an investigation last month “there was no evidence that any personal data was compromised.”

However, on Thursday the Journal de Québec said that according to a reliable source, names, addresses, social insurance numbers, and employee banking information was copied.

IT World Canada was alerted about a possible incident on July 13 by a staff member of a cybersecurity firm who watches the dark web and saw that the Aikira ransomware gang listed Tennis Canada as a victim on its data leak site. Some of the files listed by the gang as proof of the theft were named “Accounts Payable.”

In response to a query, a day later, Oliver Wheeler, the association’s manager of communications replied, “Our systems are working fine and are secure right now but thank you for bringing to our attention that this group lists Tennis Canada on its portal. We are looking into it.”

On Wednesday, Wheeler sent us this updated message:

“We can advise that Tennis Canada experienced a cyber incident in June. In accordance with our established protocols, we immediately implemented precautionary security measures and hired a team of experts to assess the situation and assist our IT department. As a result of our team’s actions, we quickly secured our systems. Since then, our systems have been operating normally, the situation was resolved, and enhanced controls were implemented to prevent this from happening again.

“Based on the investigation concluded in July by our cybersecurity experts, there was no evidence that any personal data was compromised.

“We also want to reassure all ticket-buyers that their data is safe and was not affected by the incident. Their information is hosted by a secure third-party partner. Therefore, purchasing a ticket for one of our upcoming events remains entirely safe.”

After being asked about the discrepancy between Wednesday’s statement and the Journal de Québec news story, Wheeler emailed this statement saying an incident occurred on June 8. Without detailing what the incident was, he said, “We deliberately chose not to interact with the cybercriminals that caused this incident and focused all of our energy on protecting our systems. We understand they claimed to have copied information from our systems, and we offered precautionary identity theft protection and credit monitoring to all of our employees.

“All ticket-buyer data is safe and was not affected by the incident. This information is hosted by a secure third-party partner. Therefore, purchasing a ticket for one of our upcoming events remains entirely safe.”

The post Employee banking information stolen from Tennis Canada in cyber incident: Report first appeared on IT World Canada.
Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways