CSIDB logo
Incident

North Lakes Pain Consultants

Incident posture

Attack window
May 2022
Location
Canada
Status
Historical
CIA posture
Available to members
Updated
2026-08-28 14:53

Linked entities

Victim
North Lakes Pain Consultants
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
May 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Regina Public Schools experienced a disruptive cyberattack prompting a system-wide shutdown of all internet-dependent services, including email and educational platforms, to contain the breach. The incident involved ransomware deployed by the BlackCat/ALPHV group, known for such attacks, with a threatening note appearing on compromised network devices, severely disrupting administrative operations and student learning activities reliant on online tools.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around May 27, 2022, Regina Public Schools experienced a disruptive cyberattack that compelled the district to shut down all internet-dependent systems as a containment measure. The attack disrupted critical operational and educational tools, including district email services and online learning platforms, impacting daily administrative functions and classroom activities. The incident’s severity became apparent when a ransom note appeared on computers within the school network, explicitly attributing the attack to the BlackCat/ALPHV ransomware group. Cybersecurity experts familiar with BlackCat/ALPHV’s tactics confirmed the group’s reputation for deploying ransomware to encrypt victim systems and extort payments. No specific ransom demand or data compromise claims were disclosed in the initial reports reviewed by CBC News.

The immediate response focused on isolating affected systems to prevent further propagation of the attack, though the district did not publicly detail technical containment steps beyond the network-wide internet shutdown. The prolonged outage hindered communication channels and access to digital educational resources, creating operational challenges for staff and students. Regina Public Schools did not initially release information about the attack’s duration, data recovery processes, or whether law enforcement was engaged. CBC News verified the ransom note’s authenticity and the involvement of BlackCat/ALPHV through independent cybersecurity analysis but noted no additional claims or evidence regarding stolen data. The incident underscored the vulnerability of educational infrastructure to ransomware threats disrupting essential services.

Sources

Sources available to members: 1 source.

CSIDB