CSIDB logo
Incident

Royal Military College of Canada

Incident posture

Attack window
Jul 2020
Location
Canada
Status
Historical
CIA posture
Available to members
Updated
2025-12-16 00:00

Linked entities

Victim
Royal Military College of Canada
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted multiple Canadian military training institutions, including the Royal Military College of Canada, alongside RMC Saint-Jean, the Canadian Forces College in Toronto, and the Chief Warrant Officer Robert Osside Institute. The incident temporarily disabled the organizations' online networks, with reports indicating core systems across all affected schools were compromised.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 3, 2020, a cyberattack disrupted operations at four Canadian military training institutions, including Kingston’s Royal Military College (RMC). The incident was discovered that morning when the online network at RMC became temporarily disabled. The attack also affected RMC Saint-Jean in Quebec, the Canadian Forces College in Toronto, and the Chief Warrant Officer Robert Osside Institute, indicating a coordinated targeting of multiple facilities. David Skillicorn, a Queen’s University computing professor, assessed that “all their core systems got hit,” suggesting widespread infrastructure compromise across the institutions. The attack’s timing on a Friday morning coincided with operational hours, maximizing disruption to academic and administrative functions reliant on network access. No specific details about the attack vector—such as malware, ransomware, or intrusion method—were disclosed in initial reports.

The incident’s immediate impact centered on disabling critical online systems, though the full scope of data or operational consequences remained unconfirmed in early reporting. Skillicorn’s characterization of the incident as a “mysterious cyber attack” implied uncertainties regarding attribution or motive at the time of disclosure. The involvement of multiple geographically dispersed institutions pointed to a deliberate campaign against military education infrastructure rather than an isolated breach. No public statements from the affected schools or the Canadian Department of National Defence elaborated on containment measures, forensic investigations, or recovery timelines by the report’s publication. The attack highlighted vulnerabilities in military-affiliated academic networks, though no further technical specifics or long-term operational impacts were documented in the available source material.

Sources

Sources available to members: 1 source.

CSIDB