Hackers release corporate data stolen from London Drugs
Retailer London Drugs says cybercriminals who stole files from its corporate head office last month have released some of the data after it refused to pay a ransom.
The Richmond, B.C.-based company says in a statement the files may contain "some employee information," calling it a "deeply distressing" situation.
London Drugs was responding to a social media post by Brett Callow, a B.C.-based threat analyst with anti-virus software company Emsisoft, which said the hacking group LockBit had released what it claimed was the company's data.
Lockbit has been described by British authorities as "the world's most harmful cybercrime group."
Callow said LockBit released more than 300 gigabytes of data on Thursday, describing it as an "absolutely huge amount" of information that could represent hundreds of thousands or possibly even millions of individual records.
He said that if the data proved to be from London Drugs, the move suggested LockBit had "given up" on being able to monetize the attack. The release also showed the hackers' future victims what could happen if they refused to pay up, Callow said.
The statement from London Drugs said it was "unwilling and unable" to pay a ransom to hackers it described as "a sophisticated group of global cybercriminals."
It said London Drugs was notifying employees whose personal information may have been affected and offering them credit monitoring and identity theft protection services.
The company said there was no indication any patient or customer databases were compromised in the breach that forced London Drugs to shut down its stores across Western Canada after it was discovered on April 28.
It said it was reviewing the files that may have been stolen and it would contact affected employees to tell them what personal information had been compromised.
Callow said London Drugs employees who were worried about the potential release of their personal information should be "very skeptical" of any communications they receive and avoid clicking on links in any unfamiliar text messages or emails.
He said it was possible that leaked data could be downloaded and used for identity-related fraud, but there was no evidence this was happening routinely with such releases.
"For the most part, the data simply seems to sit there and generally not be misused. So this isn't a no-risk situation by any means for the individuals whose information has been compromised, but the good news is that it is fairly low risk."
Callow said the National Crime Agency of the United Kingdom led a consortium of law enforcement agencies in disrupting LockBit's activities in February.
At the time, a statement from the agency said it had infiltrated LockBit's network and taken control of its services, "compromising their entire criminal enterprise."
It described LockBit as "the world's most harmful cybercrime group," providing a global network of hackers with the tools they need to carry out attacks.
A subsequent statement issued earlier this month identified a man from Russia as the "administrator and developer of the LockBit ransomware group."
It said the man would be subject to a series of asset freezes and travel bans, and U.S. authorities were offering a reward of up to US$10 million for information leading to his arrest and conviction.
The agency said LockBit had "attempted to rebuild," but the group was running at limited capacity and the global threat it poses was "significantly reduced."
Still, it said the group had created a "new leak site."
The statement said data obtained from LockBit systems showed hackers conducted more than 7,000 attacks using their services between June 2022 and last February.
The Canadian RCMP is listed among law enforcement agencies around the world that have participated in the taskforce targeting LockBit.
It's very difficult for police in Canada to pursue cybercriminals, such as those behind LockBit, who are based outside the country, Callow said in an interview.
Russia doesn't extradite its citizens, he noted.
The hardest-hit countries in the attacks were the United Kingdom, United States, France, Germany and China, the U.K. agency said.
London Drugs closed all 79 of its stores in B.C., Alberta, Saskatchewan, and Manitoba when it became aware of the cyberattack.
All of the stores weren't open again until May 7.
The attack was part of a series of hacking incidents that included what the B.C. government called a "sophisticated" attempt by criminals to breach its systems.
This report by The Canadian Press was first published May 23, 2024.
CTVNews.ca Top Stories
![](https://www.ctvnews.ca/polopoly_fs/1.6928914.1718553679!/httpImage/image.jpg_gen/derivatives/landscape_800/image.jpg)
'We’re in pretty good shape’: Calgary goes low in water consumption after state of local emergency declared
On a day that a local state of emergency was declared in Calgary, city residents answered a request from the mayor and emergency officials to use less water.
Prince William shares childhood photo of him and King Charles III for Father's Day
Prince William on Sunday shared a photograph showing him as a child with his father, King Charles III, to mark Father’s Day in the United Kingdom this year.
Clooney and Roberts help Biden raise US$30 million-plus at a star-studded Hollywood gala
Some of Hollywood's brightest stars headlined a fundraiser for U.S. President Joe Biden that took in a record US$30 million-plus for a Democratic candidate, according to his campaign, in hopes of energizing would-be supporters for a White House contest they said may rank among the most consequential in U.S. history.
Global study ranks two Canadian cities high on list of most expensive places to buy a home
As Canadians continue to struggle with the extremely high cost of buying a home in some of the country’s major urban centres, a new global report is underscoring just how expensive some of those markets are.
Riot police in Germany intervene to stem fan clashes ahead of England vs. Serbia soccer match
England soccer fans cheer in front of police ahead the Group C match between Serbia and England at the Euro 2024 soccer tournament in Gelsenkirchen, Germany, Sunday, June 16, 2024. (AP Photo/Markus Schreiber)
A new tax filing system could give Canadians more than $1 billion in unclaimed benefits: PBO
Canadians would get more than $1 billion in unclaimed benefits each year through an automatic tax filing system, according to a report published by the Parliamentary Budget Officer (PBO).
Ottawa Food Bank receives largest donation in its 40-year history
210,000 pounds of food was delivered to the Ottawa Food Bank on Saturday, the largest donation in its 40-year history.
Halifax chef speaks about traumatic brain injury
Halifax chef Lauren Marshall was working in the Bahamas on a special event in February when she fainted and fell from a golf cart, hitting the back of her head.
Your father’s diet before you were born could have affected your health, a new study suggests
Your father's diet before you were born could have played a role in your health, a new study has found.