CSIDB logo
Incident

Aurora Cannabis

Incident posture

Attack window
Dec 2020
Location
Canada
Status
Historical
CIA posture
Available to members
Updated
2026-01-08 21:00

Linked entities

Victim
Aurora Cannabis
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Aurora Cannabis experienced a cybersecurity incident involving unauthorized access to its Microsoft SharePoint and OneDrive cloud storage systems, compromising personal information of current and former employees. The breach exposed sensitive employee data, though the company confirmed no patient information was impacted. The incident's scope remains unclear, with an undetermined number of affected individuals. Internal communications identified the event as a data breach targeting corporate cloud repositories containing worker records.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On December 25, 2020, Aurora Cannabis experienced a cybersecurity incident involving unauthorized access to its Microsoft cloud software platforms SharePoint and OneDrive. The breach compromised personal information belonging to an unspecified number of current and former employees of the Canadian cannabis producer. An email notification sent to at least one affected individual, later shared with Marijuana Business Daily, confirmed the incident date and identified the compromised systems. The company did not disclose how the intrusion was detected or whether external threat actors were responsible for the unauthorized access. Aurora Cannabis did not provide immediate details regarding the specific types of employee data exposed during the breach.

The company asserted that the incident exclusively impacted employee information, explicitly stating that no patient data was accessed or compromised. Aurora Cannabis did not release information about the total number of affected individuals or the geographic scope of the breach beyond confirming it involved both current and former workers. No public statements from the company detailed containment measures taken following the discovery of the breach. The email notification served as the primary source of information regarding the incident's occurrence and limited technical details. Marijuana Business Daily reported the breach after reviewing the notification but did not receive additional commentary from Aurora Cannabis regarding potential operational or financial impacts resulting from the data exposure.

Sources

Sources available to members: 1 source.

CSIDB