Cyber security expert weighs in on data breach at Waterloo public school board
The Waterloo Region District Public School Board has offered few public details about what it’s calling the “cyber incidents” that impacted its IT system, but one cyber security expert says the breach is concerning.
The public school board has said it was targeted by a criminal group, and confirmed data was stolen. The board has not yet outlined what data was taken.
Ali Dehghantanha, a professor of cyber security at the University of Guelph, said since the school board collects a lot of personal information, his biggest worry with the cyber breach is identity theft and that people’s private information could be used for social engineering attacks.
“If I know your kid’s name, your kid’s school, possibly even the marks of your kids, I can probably set up very interesting and sophisticated attacks and steal a lot of information from you,” he said. “Having that private information could give attackers an upper hand.”
Dehghantanha said the impact of identity theft can be long-lasting.
“Imagine I can steal information, like a SIN number from a kid who is not of age yet, keep it for some time until they get to a specific age and then start misusing it. That would be a really, really tough case to investigate.”
However, he said whoever’s information may have been compromised may not have to worry just yet. He suggested keeping a close eye on financial transactions and to be on alert for receiving random calls.
“We don’t know the scale of the information that’s been leaked out or stolen by the attackers, so currently, we are not in a position to give a good fair assessment of the impact of people.”
On Wednesday the school board said it is working to safeguard people’s personal information, but added it could take weeks before the investigation into how this happened and what was stolen is complete.
Dehghantanha said the investigation requires looking into how the attackers got to the information and what they stole.
“Most of these hacking groups are taking actions to remove their footprints,” he said. “That’s why the investigation would be very very complicated.”
He recommends businesses and corporations take the necessary steps to protect themselves from getting hacked, including changing cyber security procedures, and not storing unnecessary personal information.
“Make sure you have a proper data removal, data destruction procedure policy in place,” Dehghantanha said.
As for users, Dehghantanha said it’s best to only use websites that have two-factor authorization.
“If you make that compulsory, it works 200 times better than making your password policy sophisticated.”
The school board said it expects to release more information on the cyber incidents early next week.
CTVNews.ca Top Stories
opinion Tom Mulcair: Prime Minister Justin Trudeau's train wreck of a final act
In his latest column for CTVNews.ca, former NDP leader and political analyst Tom Mulcair puts a spotlight on the 'spectacular failure' of Prime Minister Justin Trudeau's final act on the political stage.
B.C. mayor gets calls from across Canada about 'crazy' plan to recruit doctors
A British Columbia community's "out-of-the-box" plan to ease its family doctor shortage by hiring physicians as city employees is sparking interest from across Canada, says Colwood Mayor Doug Kobayashi.
'There’s no support': Domestic abuse survivor shares difficulties leaving her relationship
An Edmonton woman who tried to flee an abusive relationship ended up back where she started in part due to a lack of shelter space.
Baseball Hall of Famer Rickey Henderson dead at 65, reports say
Rickey Henderson, a Baseball Hall of Famer and Major League Baseball’s all-time stolen bases leader, is dead at 65, according to multiple reports.
Arizona third-grader saves choking friend
An Arizona third-grader is being recognized by his local fire department after saving a friend from choking.
Germans mourn the 5 killed and 200 injured in the apparent attack on a Christmas market
Germans on Saturday mourned the victims of an apparent attack in which authorities say a doctor drove into a busy outdoor Christmas market, killing five people, injuring 200 others and shaking the public’s sense of security at what would otherwise be a time of joy.
Blake Lively accuses 'It Ends With Us' director Justin Baldoni of harassment and smear campaign
Blake Lively has accused her 'It Ends With Us' director and co-star Justin Baldoni of sexual harassment on the set of the movie and a subsequent effort to “destroy' her reputation in a legal complaint.
Oysters distributed in B.C., Alberta, Ontario recalled for norovirus contamination
The Canadian Food Inspection Agency has issued a recall due to possible norovirus contamination of certain oysters distributed in British Columbia, Alberta and Ontario.
New rules clarify when travellers are compensated for flight disruptions
The federal government is proposing new rules surrounding airlines' obligations to travellers whose flights are disrupted, even when delays or cancellations are caused by an "exceptional circumstance" outside of carriers' control.