CSIDB logo
Incident

Vancouver Coastal Health

Incident posture

Attack window
May 2020
Location
Canada
Status
Historical
CIA posture
Available to members
Updated
2025-10-30 00:00

Linked entities

Victim
Vancouver Coastal Health
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Vancouver Coastal Health experienced a ransomware attack targeting its Employee and Family Assistance Program data, prompting the organization to engage external cybersecurity experts for investigation and response. The health authority concluded there was no evidence of data theft following the malicious intrusion.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On May 21, 2020, Vancouver Coastal Health discovered malicious ransomware within data systems associated with its Employee and Family Assistance Program. The health authority immediately initiated a response by engaging external cybersecurity experts to investigate the scope and nature of the incident. The investigation focused on determining whether unauthorized access or data exfiltration had occurred alongside the ransomware deployment. No specific details were disclosed regarding the ransomware variant, initial attack vector, or duration of unauthorized access prior to detection. Vancouver Coastal Health did not publicly confirm whether the ransomware disrupted operations, affected patient care systems, or encrypted data beyond the identified program. The organization also did not specify whether a ransom demand was received or paid.

Following the investigation, Vancouver Coastal Health publicly stated in July 2020 that it found “no evidence” that data had been stolen during the incident. The health authority did not elaborate on whether data was encrypted, destroyed, or rendered inaccessible by the attack, nor did it disclose remediation costs or operational recovery timelines. No further technical details about containment measures—such as network segmentation, system restoration, or forensic methodologies—were released. The public announcement emphasized the absence of confirmed data theft but did not address potential risks to employee or patient privacy beyond the Employee and Family Assistance Program. Vancouver Coastal Health did not attribute the attack to any specific threat actor or group in its communications.

Sources

Sources available to members: 1 source.

CSIDB