Menu
Browse
Date:

Nov 2019

Location:

Canada

Summary

The Waterloo Catholic District School Board experienced a significant malware attack that disrupted its operations, discovered early on a Sunday. By Wednesday, the organization remained actively engaged in response efforts to contain and address the incident, with chief managing officer John Shewchuk confirming the severity of the cyberattack. The malware incident prompted ongoing mitigation actions, though specific technical details or compromised data types were not disclosed in initial reports.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

The Waterloo Catholic District School Board experienced a significant malware attack that disrupted its operations in late November 2019. Chief Managing Officer John Shewchuk confirmed the incident was under active investigation on Wednesday, November 20, though the attack was first detected earlier that same week. The board's technology team identified anomalous activity during routine monitoring early on Sunday, November 24, triggering immediate incident response protocols. While technical specifics about the malware variant and intrusion vector weren't publicly disclosed, the attack caused substantial operational disruptions affecting administrative systems and communication platforms. Shewchuk characterized the event as a coordinated cyber intrusion requiring sustained remediation efforts across the board's digital infrastructure.

Cyber Incident Image

Response activities included isolating compromised systems, deploying forensic cybersecurity experts, and coordinating with law enforcement agencies. The board prioritized restoring critical educational systems while conducting damage assessments to determine potential data exposure. No explicit evidence of data exfiltration was confirmed in initial reports, though investigators examined whether personally identifiable information of students or staff might have been accessed. Operational continuity measures were implemented to maintain educational services during the outage, with staff reverting to manual processes for attendance tracking and communication where necessary. The board maintained public transparency through periodic updates while refraining from speculative statements about attribution or long-term impacts until forensic analysis concluded.

Sources
Sources available to members
1 source