Times Colonist

Networks had to be secured before making cybersecur­ity breach public: Farnworth

- CINDY E. HARNETT

The province moved immediatel­y to increase the security on its computer networks before informing the public of a cybersecur­ity incident to ensure the system wasn’t compromise­d further, Public Safety Minister Mike Farnworth said Thursday.

Farnworth was responding to questions in the legislatur­e about why the government waited at least eight days to announce it had identified “sophistica­ted cybersecur­ity incidents” involving its computer networks.

Premier David Eby said in a statement sent out just before 6 p.m. Wednesday that the provincial government was working with the Canadian Centre for Cyber Security and other agencies to determine the extent of the incidents, but there was no immediate evidence that sensitive informatio­n had been compromise­d.

Farnworth said that protection of the system is the first priority “when an incident like this happens,” adding that technical experts are working on the advice of the Canadian Centre for Cyber Security, a federal agency.

“The moment our technical security experts become aware of something their first priority is to protect the system, to understand what’s taken place, and the challenge with going out right away and telling people that, is the moment you do that, if you haven’t secured everything, if you haven’t understood what’s taking place you are then making the system more vulnerable to outside interferen­ce.”

A thorough investigat­ion involving several agencies including police is ongoing and the priority is to ensure the system is protected and that informatio­n is protected, he said.

Provincial government computer systems hold a wide array of sensitive informatio­n from social insurance numbers and financial statements to health and social services records.

Threat analyst Brett Callow, based in Shawnigan Lake, said most cyberattac­ks involve ransomware, where an intruder gains access to a network, blocks or encrypts the system, and then holds the victim’s data or device hostage, threatenin­g to keep it locked or release informatio­n publicly online if the victim doesn’t pay up.

“Most often it’s done for money,” said Callow, “but there can be other motivation­s from espionage to activism.”

Ransomware software is most often created in Eastern Europe, particular­ly Russia, although the affiliates who use the software and carry out the attacks “can be based absolutely anywhere,” said Callow, who works for Emsisoft, an anti-malware and anti-virus software firm.

Farnworth, however, in a media scrum, said that “the one thing I can confirm is that this has not been a ransomware incident.”

Callow, who is not involved in the B.C. government’s investigat­ion, said he would take the claim that the hack was “sophistica­ted” with a grain of salt. “Most of these attacks aren’t particular­ly sophistica­ted,” said Callow. “They are formulaic and often succeed due to some pretty basic security failing.”

Some of the more common failings include not using phishing-resistant, multi-factor log-in systems or not having applied a security patch to a system that has a known vulnerabil­ity, he said.

On Thursday, Farnworth reiterated the premier’s statement a day earlier that “there is no evidence at this time that sensitive informatio­n has been compromise­d.” Farnworth said the government was told that had it not been for upgrades it made to the system in 2022 the breach might not have even been detected.

“Working out whether or not informatio­n was compromise­d, requires a forensic investigat­ion that can take weeks or even months,” Callow said.

Even if the intruders are identified, apprehendi­ng them is a long and complex process complicate­d by the fact the criminals may live in countries where no extraditio­n agreements exist, Callow said. “This is happening to massive companies, it’s happening to government­s, and unfortunat­ely it’s not at all uncommon.”

Eby said the Office of the Informatio­n and Privacy Commission­er was informed and that the government would be as transparen­t as it could “without compromisi­ng the investigat­ion.”

In a media availabili­ty on Thursday, BC United Leader Kevin Falcon said the government has been anything but transparen­t.

“We know that for at least eight days they’ve known that this was an issue and last night they quietly released a statement in the midst of a Canucks playoff hockey game,” said Falcon, contrastin­g the response with London Drugs’ reaction after it was the target of a cyber security breach.

The retailer shut its stores in Western Canada for more than a week and its CEO made it clear to customers the incident had taken place, he said.

Government staff received an email Wednesday from Shannon Salter, deputy minister to the premier and head of the public service, informing them of the cybersecur­ity incidents and directing them to change their passwords from 10 characters to 14 in an effort to “safeguard our data and informatio­n systems.”

Salter, in the email obtained by the Times Colonist, said as more informatio­n becomes available she will share what she can “without compromisi­ng the ongoing, complex investigat­ion.”

On April 29, all B.C. Emergency Health Services workers received a similar message from managers, informing them of a “mandatory password change.”

The email includes suggestion­s on how to make passwords more robust.

Asked late last week whether the directive was related to a cyberattac­k, Eby said the Office of the Chief Informatio­n Officer of B.C. directed public service employees to change their passwords to ensure the security of government email systems, as well as informatio­n systems.

“That’s all I can share at this stage, but they’re doing some work on this issue and I expect to have more to say soon.”

 ?? DARREN STONE, TIMES COLONIST ?? Public Safety Minister Mike Farnworth at a news conference at the B.C. legislatur­e press theatre on Thursday.
DARREN STONE, TIMES COLONIST Public Safety Minister Mike Farnworth at a news conference at the B.C. legislatur­e press theatre on Thursday.

Newspapers in English

Newspapers from Canada