Photo of GAC Building in Canada
© RSTPIERR/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

A significant breach at a major Canadian foreign affairs department may have exposed the data of numerous employees. Global Affairs Canada (GAC) only discovered that one of its internal virtual private networks (VPN) had been compromised a month after the initial breach.

The breach exposed employee emails and various types of files, including “sensitive correspondence and some intelligence,” Canada’s national broadcaster CBC. said on Tuesday. It specifically impacted files on personal and shared drives, which could include credit card and banking data, CBC added.

“Early results indicate there has been a data breach and that there has been unauthorized access to the personal information of users, including employees. The Department is contacting those affected with mitigation measures to ensure that sensitive and personal information is secure,” GAC spokesperson Marilyne Guèvremont said in a statement shared with the National Post.

Month-Long Breach

GAC’s internal network is thought to have been compromised on December 20, 2023. But, the organization only found out on January 24.

“A breach of that duration is bound to be serious,” Wesley Wark, a national security expert at the University of Ottawa, told CBC. “Global Affairs Canada holds a lot of classified and sensitive information … It is a natural target for hacking but it’s also vulnerable and holds important data,” he explained.

According to the National Post, Global Affairs Canada did not announce the breach until questioned about the incident. An internal memo shared by the department said anyone using a “SIGNET” (Secure Integrated Global Network) laptop for remote VPN connections to GAC headquarters may have been affected.

An investigation has been launched into the breach. According to CBC, the Canadian Centre for Cyber Security is working alongside Shared Services Canada to assess the full extent of the damage.

As a result of the breach, GAC employees, particularly those based in Canada and with security clearance, are reportedly facing disruptions in their ability to work remotely. Meanwhile, measures are being taken to safeguard sensitive information and monitor financial accounts for unauthorized activity.

This is not the first time GAC has been the victim of a major cyber incident. In early 2022, a cyber attack caused a multi-day shutdown of numerous GAC internal systems.

This GAC is responsible for Canada’s diplomatic and international policy and holds critical information like diplomatic communications and trade data. It also manages significant financial resources, including multi-billion dollar budgets, making it a key target for cybercriminals and espionage operations.

‘A Treasure Trove of Information’

Neil Bisson, the Director of Global Intelligence Knowledge Network, described the leaked data as a “treasure trove” of information. He said the incident poses a substantial threat from an intelligence perspective as emails, calendars, and contact lists were among the leaked data.

According to Bisson, the extended duration of the breach — lasting at least a month — was not entirely unexpected. He explained that in most cases involving malicious actors, they can infiltrate a system and remain undetected for years before being discovered.

In the wake of this breach, the importance of cybersecurity for organizations is evident. It’s important to use a secure corporate VPN platform to protect your data from hackers and other cyber threats. Check out our guide to the best corporate VPNs to see our top picks.

Employee devices may also be a gateway for breaches in a corporate network. We recommend educating employees about cybersecurity best practices to keep their personal devices safe.

For more news, follow us on X (Twitter), Threads, and Mastodon!

Leave a comment