CSIDB logo
Incident

Canadian Forces College

Incident posture

Attack window
Jul 2020
Location
Canada
Status
Historical
CIA posture
Available to members
Updated
2025-12-16 00:00

Linked entities

Victim
Canadian Forces College
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Multiple Canadian military training institutions, including the Canadian Forces College, Royal Military College in Kingston, RMC Saint-Jean, and the Chief Warrant Officer Robert Osside Institute, were targeted in a cyberattack that disrupted their online networks. The incident impacted core systems across the affected schools, temporarily disabling critical infrastructure. Described as a mysterious attack by reports, the breach caused significant operational interruptions but no further details on the attackers or specific methodologies were disclosed in initial findings.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On the morning of July 3, 2020, a cyberattack disrupted the online networks of four Canadian military training institutions: Kingston’s Royal Military College, RMC Saint-Jean in Quebec, the Canadian Forces College in Toronto, and the Chief Warrant Officer Robert Osside Institute. The attack was discovered when the schools experienced system-wide disruptions, temporarily disabling their core operational networks. David Skillicorn, a Queen’s University computing professor, publicly assessed that "all their core systems got hit," indicating a broad compromise of essential infrastructure. The incident rendered critical online services inoperable across all four institutions, though the specific duration of the outage was not detailed in available reports. No initial claims of responsibility or motives were disclosed, with media describing the incident as a "mysterious cyber attack." The coordinated nature of the attack across geographically dispersed schools suggested a targeted effort against military education infrastructure.

Authorities did not publicly release technical details about the attack vector, malware used, or data compromise scope following the discovery. The primary confirmed impact was the immediate operational disruption to online networks, affecting administrative and educational functions reliant on digital systems. No information was disclosed regarding containment measures, forensic investigations, or recovery timelines by the Canadian military or affected institutions in the immediate aftermath. The incident highlighted vulnerabilities in national defense-adjacent educational infrastructure but yielded no further actionable details about threat actors or long-term consequences in the available public reporting.

Sources

Sources available to members: 1 source.

CSIDB