Menu
Browse

Cyber Incident Victim: Peel District School Board

Date:

Jan 2021

Location:

Canada

Summary

A cyber security incident at Peel District School Board caused significant system disruptions after malicious actors encrypted files and infrastructure components. The board assured stakeholders that no personal or sensitive data appeared compromised and worked diligently to recover encrypted systems and resume normal operations, prioritizing service restoration and security evaluations throughout the remediation process.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 3 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On January 26, 2021, the Peel District School Board (PDSB) experienced a cyber security incident that disrupted its normal operations. The attack involved the encryption of files and systems, leading to widespread technical outages across the organization’s infrastructure. The board publicly acknowledged the incident through a statement posted on Twitter on the evening of January 28, confirming the encryption event while emphasizing ongoing efforts to restore services. Initial assessments indicated the disruption affected multiple operational systems, though the board did not specify which applications or data repositories were compromised. The incident prompted an immediate response from PDSB’s technical teams to isolate affected systems and prevent further spread of the encryption. No explicit details were provided regarding the initial detection method or the exact time of the attack’s onset beyond the January 26 date.

Cyber Incident Image

The PDSB’s primary focus following containment was restoring system functionality and investigating potential data exposure. In its public communications, the organization stated there was no evidence suggesting unauthorized access to personal or sensitive information, though it did not disclose whether forensic audits or third-party analyses corroborated this finding. Recovery efforts prioritized returning to normal operations, with the board assuring stakeholders that work was underway to resolve the outages. The Twitter announcement served as the central public update channel, reflecting a coordinated response to manage communications during the disruption. No ransomware group claimed responsibility, and the board did not reference demands or payment negotiations. The incident’s operational impact persisted beyond the initial acknowledgment, with restoration timelines left unspecified in available disclosures.

Sources
Sources available to members
1 source