Ransom demand behind B.C. health authority cyberattack, premier reveals
British Columbia’s premier has revealed a cyberattack on a health authority is another ransomware incident, while experts say it appears to be a different group of criminals than those behind two other recent attacks.
The First Nations Health Authority, which provides services and healthcare to Indigenous people across the province, announced a “cyber security incident” on Wednesday but provided little detail.
When David Eby was asked about the incident at an unrelated press conference on Thursday, he told reporters cyberthreats are growing and that “we have seen high-profile retailers like London Drugs be the victim of ransomware, and now the First Nations Health Authority.”
The data stolen by cybercriminals and now being used to blackmail officials is considerable, with samples already posted on the dark web: the signatures of senior FNHA staff on seven-figure contracts with medical providers, legal agreements with First Nations governments, as well as emails between providers and patients.
Other health authorities affected?
One of those emails involves a staffer in the Northern Health Authority, so CTV News asked the health minister what other health authorities could be compromised. FNHA has only a handful of facilities and patients often get medical care through the five geographic health authorities (Island Health, Vancouver Coastal, Fraser, Interior, and Northern Health).
“There's no evidence that the health authorities have been at all affected by the breach at the First Nations Health Authority,” said Adrian Dix, who seemed unaware of the data package posted to the dark web. “They're taking it extremely seriously, they're bringing in all of the required supports to provide maximum protection to both data and to people.”
How this hack is different
CTV News consulted several cybersecurity experts about this latest hack. One pointed to sloppy coding on the FNHA website’s contact page, while others said it appears a different group of hackers is behind the London Drugs ransomware attack since the information was posted by another group.
“The blueprint for how these attacks unfold would be very similar to what happened at London Drugs,” explained Sophos Security analyst, Chester Wisniewski. “There's almost a manual to teach these hackers how to do these attacks; start with human resources information, then target finance, then target legal, then go through peoples' inboxes and look for the word ‘password’ or this type of thing.”
Eby emphasized that the attack on provincial systems earlier this month is likely separate, but would not commit to expanding funding or staffing to combat the rising threat, having made millions in investments in the last few years.
“In 2022 we deployed additional resources to be able to detect and prevent cyberthreats, that enabled us to detect and begin the work to address the cyberattack we've faced from a state-level actor,” he said.
Wisnkiewski warned that those problems are much harder to solve.
“An attacker that is a nation-state is typically carrying out a spy mission or a military mission and they won't give up no matter how hard you defend yourself,” he said. “The criminals behind the attack on the health authority and London Drugs are really just after money.” https://bc.ctvnews.ca/all-provincial-employees-in-b-c-directed-to-change-passwords-1.6869968
CTVNews.ca Top Stories
![](https://www.ctvnews.ca/polopoly_fs/1.6976926.1721883767!/httpImage/image.png_gen/derivatives/landscape_800/image.png)
LIVE UPDATES Critical infrastructure 'successfully protected': Jasper park officials
Jasper National Park officials in an update said all critical infrastructure in the townsite has been 'successfully protected, including the hospital, emergency services building, both elementary and junior/senior schools, activity centre and wastewater treatment plant.'
BREAKING Canadian Olympic Committee removes women's soccer team's head coach over drone scandal
The Canadian Olympic Committee has removed women's national soccer team head coach Bev Priestman over a drone scandal, according to a press release from the organization.
'I was just shocked': Jasper lodge owner on seeing property destroyed by wildfire
On Wednesday night, the owner of Maligne Lodge in Jasper, Alta., was shocked to receive a photo of her business engulfed in flames.
Prince William's 2023 salary revealed in new report
Newly released financial reports show that William, the Prince of Wales, drew a salary of $42.1 million last fiscal year, his first since inheriting the vast and lucrative Duchy of Cornwall.
Yukon woman narrowly escapes bear attack, credits hair clip
A woman in Yukon believes her hair clip helped save her during a bear attack.
P.E.I. and New Brunswick among most overworked provinces in Canada, study finds
A study says Prince Edward Island is the second most overworked province in Canada based on average weekly hours worked, while New Brunswick falls in third.
Mary-Ellen Turpel-Lafond likely has Indigenous DNA: report
The Law Society of British Columbia says a DNA test shows a former judge and Order of Canada recipient accused of falsely claiming to be Cree "most likely" has Indigenous heritage.
Alberta premier says a third, perhaps half, of all Jasper buildings destroyed by fire
Alberta Premier Danielle Smith says early reports indicate a third and perhaps up to half of all buildings in the historic Rocky Mountain resort town of Jasper have burned in a wildfire.
OPINION Prince Harry: Press intrusion and the family rift explored in new doc
Prince Harry, the Duke of Sussex, has once again found himself at the centre of media attention following his recent interview as part of 'Tabloids on Trial,' an ITV documentary on phone hacking and tabloid intrusion.