CSIDB logo
Incident

Okanagan College

Incident posture

Attack window
Jan 2023
Location
Canada
Status
Historical
CIA posture
Available to members
Updated
2025-10-15 00:00

Linked entities

Victim
Okanagan College
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Jan 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Okanagan College experienced a cyber attack detected during routine IT surveillance, prompting an immediate shutdown of network access across all campuses within 45 minutes to mitigate the threat. The incident disrupted internet, wireless, internal student and staff information systems, phone lines, and campus security communications, impacting approximately 16,000 students and 1,200 staff. While Moodle access was partially restored via an alternate link, the college engaged external cybersecurity experts to investigate potential compromises of personal information and advised vigilance against phishing attempts. The institution emphasized restoring services securely but confirmed ongoing network outages affecting its public website and email systems during the response.

Motives

Detailed motive labels are available to members.

4 motives

TTPs

Detailed technique labels are available to members.

5 techniques

Description

On January 9, 2023, Okanagan College’s IT Services team detected a cybersecurity incident during routine surveillance at approximately 6:15 a.m. The attack involved an unrecognized external agent, prompting immediate containment measures. Within 45 minutes, IT Services disabled network access across all campuses to prevent further intrusion and initiated an investigation. The college engaged external cybersecurity experts to assist in assessing the breach and restoring systems. The incident caused widespread network outages, affecting internet connectivity, wireless services, internal student and staff information systems, and internet-based phone lines, including campus security communications. By January 11, partial access to the learning management system Moodle was restored via a dedicated URL, though core network services remained offline. The outage also disrupted the college’s public website and all-user email distribution, complicating internal communications.

Approximately 16,000 students and 1,200 staff were impacted by the prolonged service disruption. As a precaution, the college provided alternative cellular contact numbers for campus security across its Kelowna, Salmon Arm, Penticton, and Vernon campuses. President Neil Fassina issued a public notification on January 11, advising vigilance against potential phishing attempts or fraudulent communications impersonating the institution. The college emphasized it was investigating whether personal data had been compromised but had not confirmed any specific breaches as of January 12. IT Services continued incremental recovery efforts, though system availability remained unchanged by the morning of January 12, according to status updates. Restoration priorities focused on secure reactivation of services while preserving evidence for the ongoing forensic investigation.

Sources

Sources available to members: 2 sources.

CSIDB