CSIDB logo
Incident

Waterloo Catholic District School Board

Incident posture

Attack window
Nov 2019
Location
Canada
Status
Historical
CIA posture
Available to members
Updated
2025-11-26 00:00

Linked entities

Victim
Waterloo Catholic District School Board
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Waterloo Catholic District School Board experienced a significant malware attack that disrupted its operations, discovered early on a Sunday. By Wednesday, the organization remained actively engaged in response efforts to contain and address the incident, with chief managing officer John Shewchuk confirming the severity of the cyberattack. The malware incident prompted ongoing mitigation actions, though specific technical details or compromised data types were not disclosed in initial reports.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

The Waterloo Catholic District School Board experienced a significant malware attack that disrupted its operations in late November 2019. Chief Managing Officer John Shewchuk confirmed the incident was under active investigation on Wednesday, November 20, though the attack was first detected earlier that same week. The board's technology team identified anomalous activity during routine monitoring early on Sunday, November 24, triggering immediate incident response protocols. While technical specifics about the malware variant and intrusion vector weren't publicly disclosed, the attack caused substantial operational disruptions affecting administrative systems and communication platforms. Shewchuk characterized the event as a coordinated cyber intrusion requiring sustained remediation efforts across the board's digital infrastructure.

Response activities included isolating compromised systems, deploying forensic cybersecurity experts, and coordinating with law enforcement agencies. The board prioritized restoring critical educational systems while conducting damage assessments to determine potential data exposure. No explicit evidence of data exfiltration was confirmed in initial reports, though investigators examined whether personally identifiable information of students or staff might have been accessed. Operational continuity measures were implemented to maintain educational services during the outage, with staff reverting to manual processes for attendance tracking and communication where necessary. The board maintained public transparency through periodic updates while refraining from speculative statements about attribution or long-term impacts until forensic analysis concluded.

Sources

Sources available to members: 1 source.

CSIDB