Menu
Browse

Cyber Incident Victim: Quebec Liberal Party

Date:

Jun 2016

Location:

Canada

Summary

An unknown hacker accessed the Quebec Liberal Party's video conferencing system by exploiting a security flaw and using the default administrator password, enabling unauthorized surveillance of internal meetings between regional branches and remote activation of camera feeds at will. The individual, acting as a white hat, disclosed the intrusion to the party via a journalist and provided evidence including meeting details and screenshots; officials confirmed the breach but stated no nationally sensitive information was compromised, subsequently patching the vulnerability and changing credentials to secure the system.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

In June 2016, an unidentified white-hat hacker gained unauthorized access to the Quebec Liberal Party’s (PLQ) video conferencing system, enabling surveillance of internal meetings. The hacker exploited a security flaw in the software and discovered the system was configured with its factory-default administrator password, allowing repeated logins over an unspecified period. After accessing the platform, the individual observed multiple PLQ meetings between the party’s Quebec and Montreal branches, capturing details of discussions and recording video footage at will. To validate his claims, the hacker provided screenshots of the compromised feeds and disclosed specific meeting topics to a Le Journal de Montréal reporter, whom he contacted anonymously to relay the vulnerability. The intruder emphasized non-malicious intent, framing the intrusion as a responsible disclosure effort rather than an attack. PLQ officials later confirmed the breach but clarified that no nationally sensitive matters were discussed during the monitored sessions.

Cyber Incident Image

Upon being alerted to the breach via the journalist, PLQ initiated an investigation that confirmed the hacker’s access through the default credentials and software vulnerability. The party’s IT team resolved the issue within days by patching the security flaw and changing the system password, though they did not specify whether the default password or the software bug was the primary attack vector. No evidence suggested data exfiltration or additional system compromises beyond the video conferencing platform. The incident remained confined to unauthorized viewing of meetings, with no reported operational disruptions or financial impacts. PLQ did not disclose whether they notified law enforcement or implemented further security audits beyond the immediate remediation.

Sources
Sources available to members
1 source