CSIDB logo
Incident

British Columbia Wildfire Management Branch

Incident posture

Attack window
Oct 2014
Location
Canada
Status
Historical
CIA posture
Available to members
Updated
2026-09-03 15:48

Linked entities

Victim
British Columbia Wildfire Management Branch
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The British Columbia Wildfire Management Branch experienced a data breach when an unauthorized user with an Internet address based in Estonia accessed a new-recruitment database. The database, which contained information dating back to 2004, held names, contact information, birth dates, drivers' licence numbers, and job evaluation information for both successful and unsuccessful applicants to seasonal wildfire crew positions, affecting approximately 15,000 individuals. Public access to the website was shut down as soon as the breach was discovered, and the government began notifying those impacted while offering free credit protection services. The Office of the Information and Privacy Commissioner was notified of the incident and is monitoring the situation. Information Technology specialists are investigating how the breach occurred and exploring measures to prevent future incidents.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 24, 2014, an unauthorized user with an Internet address based in Estonia gained access to a new-recruitment database operated by the British Columbia Ministry of Forests' Wildfire Management Branch. Brian Simpson, the executive director of the Wildfire Management Branch, disclosed the incident publicly on October 14, 2014, stating that the database had been targeted by an outside party. The database contained information about individuals who had applied for seasonal wildfire-fighting positions with the provincial government. According to Simpson, the breach was the first of its kind he had encountered in his 37 years with the ministry, though he acknowledged that unauthorized data intrusions had become an increasingly common occurrence in the information age, affecting both public and private sector organizations. Once the breach was identified, public access to the website hosting the recruitment database was shut down to prevent further unauthorized access.

The compromised database held records dating back to 2004, encompassing approximately ten years of application data. It included the names, contact information, birth dates, drivers' licence numbers, and job evaluation information of both successful and unsuccessful applicants for wildfire crew positions. In total, the personal information of roughly 15,000 individuals may have been accessed during the incident. The Ministry of Forests announced it was working to notify all potentially affected people and was offering free credit protection services to those impacted by the breach. A dedicated telephone hotline, 1-844-456-2284, was established for individuals who believed their information may have been compromised so they could seek assistance and clarification regarding the incident.

The Office of the Information and Privacy Commissioner for British Columbia was formally notified of the breach on October 3, 2014, approximately nine days after the unauthorized access occurred on September 24. Spokeswoman Michelle Mitchell confirmed that the public watchdog had received notification through the Ministry of Forests' website and was actively monitoring the situation. The breach drew comparisons to a separate incident earlier that summer in July 2014, when the B.C. Ministry of Health revealed that an unauthorized person using a doctor's PharmaNet account had accessed names, birth dates, addresses, phone numbers, and health numbers of individuals. Simpson noted that Information Technology specialists were engaged in studying precisely how the breach had occurred and what additional security measures could be implemented to prevent similar incidents in the future, while candidly observing that as new protective measures are developed, attackers frequently devise methods to circumvent them.

Sources

Sources available to members: 1 source.

CSIDB