Menu
Browse

Cyber Incident Victim: Aurora Cannabis

Date:

Dec 2020

Location:

Canada

Summary

Aurora Cannabis experienced a cybersecurity incident involving unauthorized access to its Microsoft SharePoint and OneDrive cloud storage systems, compromising personal information of current and former employees. The breach exposed sensitive employee data, though the company confirmed no patient information was impacted. The incident's scope remains unclear, with an undetermined number of affected individuals. Internal communications identified the event as a data breach targeting corporate cloud repositories containing worker records.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On December 25, 2020, Aurora Cannabis experienced a cybersecurity incident involving unauthorized access to its Microsoft cloud software platforms SharePoint and OneDrive. The breach compromised personal information belonging to an unspecified number of current and former employees of the Canadian cannabis producer. An email notification sent to at least one affected individual, later shared with Marijuana Business Daily, confirmed the incident date and identified the compromised systems. The company did not disclose how the intrusion was detected or whether external threat actors were responsible for the unauthorized access. Aurora Cannabis did not provide immediate details regarding the specific types of employee data exposed during the breach.

Cyber Incident Image

The company asserted that the incident exclusively impacted employee information, explicitly stating that no patient data was accessed or compromised. Aurora Cannabis did not release information about the total number of affected individuals or the geographic scope of the breach beyond confirming it involved both current and former workers. No public statements from the company detailed containment measures taken following the discovery of the breach. The email notification served as the primary source of information regarding the incident's occurrence and limited technical details. Marijuana Business Daily reported the breach after reviewing the notification but did not receive additional commentary from Aurora Cannabis regarding potential operational or financial impacts resulting from the data exposure.

Sources
Sources available to members
1 source