Cyber Incident Victim: Saskatchewan Polytechnic
Date:
Nov 2020
Location:
Canada
Summary
A cybersecurity incident disrupted operations at Saskatchewan Polytechnic, leading to the cancellation of both online and in-person classes. The institution suspended academic activities for multiple days while its IT teams collaborated with external specialists to restore compromised systems, prioritizing the recovery of online learning platforms. The attack necessitated a full shutdown of critical infrastructure as response efforts focused on containment and restoration.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or around November 2, 2020, Saskatchewan Polytechnic experienced a cybersecurity attack that disrupted its operations, leading to the cancellation of all online and in-person classes. The institution announced the shutdown immediately following the detection of the incident, with classes suspended until at least November 5 to allow recovery efforts to proceed. Information technology staff initiated emergency protocols, collaborating with external cybersecurity experts to assess the damage and restore critical systems. The administration prioritized the restoration of online learning platforms to minimize academic disruption, though no specific technical details about the attack vector or compromised systems were disclosed publicly. No threat actor claimed responsibility, and the institution did not confirm whether data exfiltration or ransomware encryption occurred.

The attack caused significant operational interruptions, halting educational activities across all campuses and delivery modes. Saskatchewan Polytechnic’s decision to suspend classes for multiple days underscored the severity of the incident, though the institution did not quantify the number of affected students or staff. Recovery efforts focused on system restoration rather than public disclosure of technical specifics, with no subsequent updates confirming full resolution by November 5. The incident highlighted vulnerabilities in the institution’s infrastructure but yielded no confirmed information about financial losses, data breaches, or long-term remediation costs. Restoration timelines and mitigation strategies remained confined to internal coordination between institutional personnel and third-party responders.
