CSIDB logo
Incident

Association of Canadian Travel Agencies and Travel Advisors

Incident posture

Attack window
Apr 2025
Location
Canada
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 11:12

Linked entities

Victim
Association of Canadian Travel Agencies and Travel Advisors
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Association of Canadian Travel Agencies and Travel Advisors experienced a cybersecurity incident resulting in unauthorized access to its email system. The organization became aware of the breach and responded by engaging IT and forensic experts to investigate and contain the issue. While some personal data stored in member profiles may have been potentially accessed, no financial or payment information was involved, and there is no evidence that the information has been misused. In response, additional safeguards were implemented to protect member data, and the appropriate authorities were notified. Members were advised to monitor their accounts for unusual activity, update passwords, and exercise caution when sharing personal information. The organization's president communicated directly with members to inform them of the situation and the steps being taken.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 21, 2025, the Association of Canadian Travel Agencies and Travel Advisors (ACTA) became aware of a cyber security incident that resulted in unauthorized access to the organization's email system. The discovery of the breach triggered immediate action, as ACTA moved swiftly to investigate the scope and contain the issue by engaging IT and forensic experts. In a letter dated July 29, ACTA President Suzanne Acton-Gervais communicated the details of the incident to the organization's membership, informing them of the timeline and nature of the unauthorized access. The breach was confined to ACTA's email environment, and the organization moved quickly to assess what information may have been exposed through that system. The specific vector of attack and the identity of the threat actor were not disclosed in the communication to members, and no public technical details about how the email system was compromised have been reported in the available source material. The detection occurred on the same day as the incident itself, based on the language used in ACTA's letter indicating that the organization "became aware" of the cyber security incident on April 21, 2025, though the precise means of detection—whether through internal security monitoring, third-party notification, or member complaint—has not been specified.

The scope of the incident was limited to data contained within ACTA's email system and information stored in member profiles on or before April 21, 2025. According to ACTA's communication, some personal data may have been potentially accessed by the unauthorized party, though the organization expressed confidence that no financial or payment information was involved in the breach. The information at risk was characterized as limited to what was stored in ACTA member profiles as of the date of the incident. ACTA advised members that, at the time of notification, there was no evidence that any accessed information had been misused. To assist members in determining whether their information may have been involved, ACTA established a process through their website where members could log into their accounts, access their membership section, and review what information may have been present in the email system at the time of the breach. The specific categories of personal data potentially exposed—whether names, contact information, employment details, or other identifiers maintained in member profiles—were not enumerated in the public communication. The exact number of affected members was not disclosed in the available reporting.

In response to the incident, ACTA implemented additional safeguards designed to further protect member information and notified the appropriate authorities, as stated in the letter from President Acton-Gervais. The engagement of IT and forensic experts formed part of the immediate response, supporting both the investigation into the unauthorized access and the containment of the issue within the email system. ACTA also designated a Privacy Officer, Avery Campbell, as the point of contact for members who had concerns or questions arising from the breach notification. The organization urged members to follow standard identity protection practices as a precaution, including monitoring accounts for unusual activity, updating account passwords, and exercising caution when sharing personal information. The notification to members came approximately three months after the incident was discovered, with the warning letter issued on July 29, 2025, while the breach occurred in April 2025. ACTA apologized to members for any inconvenience caused by the incident and reiterated its commitment to supporting and advocating for Canada's retail travel and tourism industry, emphasizing the value placed on the trust members place in the organization. The travel industry trade publication Travelweek reported on the warning issued to ACTA members on April 21, 2025, based on the July 29 letter, bringing public attention to the cyber security incident affecting the Canadian travel advisor association.

Sources

Sources available to members: 1 source.

CSIDB