Sun Media Corp
Incident posture
Linked entities
- Victim
- Sun Media Corp
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Canoe.ca disclosed that a breach exposed personal information of roughly one million users, including names, email addresses, mailing addresses and telephone numbers, collected through contests, forums, comment sections and personal pages. The investigation found no financial data or social insurance numbers among the compromised records. After discovering the incident, the organization launched an investigation, enlisted security experts, and informed the RCMP, the Office of the Privacy Commissioner and relevant provincial privacy authorities. It also provided a contact number for affected users seeking assistance.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Canoe.ca, a free news and entertainment portal operated by MediaQMI Inc. and owned by Sun Media Corp. prior to 2015, issued a public notice on September 2, 2017, informing users that certain databases containing records from 1996 to 2008 had been accessed without authorization. The notice explained that the breach was discovered shortly before the announcement and that an immediate investigation was launched to determine the scope and nature of the compromised information. According to the statement, the compromised databases held personal data belonging to approximately one million Anglophone and Francophone users who had interacted with the Canoe sites during the specified timeframe. The data had been collected through various user‑generated activities such as contest entries, forum participation, comment submissions, and the hosting of personal pages.
The investigation revealed that the exposed information included names, email addresses, mailing addresses, and telephone numbers, but contained no financial details such as credit card numbers or social insurance numbers. It was explicitly noted that no data collected after 2008 was affected by the breach, limiting the exposure to the historical records from the 1996‑2008 period. The organization emphasized that the breach did not involve any payment‑card or government‑identifier information, thereby reducing the risk of direct financial fraud for the affected individuals. The statement also clarified that the personal information had been provided voluntarily by users for the aforementioned site features.
In response to the incident, Canoe.ca engaged recognized data security experts to assist with a thorough investigation and to implement remediation measures aimed at securing the affected systems. The company reported that it had notified the Royal Canadian Mounted Police, the Office of the Privacy Commissioner of Canada, and all relevant provincial privacy commissioners about the security breach. Canoe.ca issued a sincere apology to its users and affirmed that it was making every effort to locate and contact every individual whose data might have been compromised during the illegal access. To facilitate user inquiries, the organization provided a toll‑free telephone number, 1‑833‑370‑2898, for anyone concerned about the breach to call for further information and assistance.
Sources
Sources available to members: 1 source.