CSIDB logo
Incident

Confederation College

Incident posture

Attack window
Feb 2020
Location
Canada
Status
Historical
CIA posture
Available to members
Updated
2025-11-01 00:00

Linked entities

Victim
Confederation College
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Confederation College experienced a malware incident that disrupted numerous online services, prompting an investigation by technology staff and external cybersecurity experts. While the institution confirmed no evidence of unauthorized access or exfiltration of student personal information during the initial assessment, a forensic review remains ongoing to definitively assess potential data compromise. The college committed to directly notifying affected individuals if the investigation reveals any personal information was removed.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

3 techniques

Description

In late January or early February 2020, Confederation College experienced a malware incident that disrupted many of its online services over a weekend. Technology staff initiated an investigation into a potential security breach following the service outages. The disruption impacted core digital operations, though the specific systems affected were not detailed publicly. College personnel worked to restore functionality while assessing whether the malware incident resulted in unauthorized access to sensitive information. At the time of reporting on February 1, no evidence had been found indicating exfiltration of student personal information. The institution engaged external cybersecurity experts to conduct a forensic examination of the incident to determine its full scope and nature.

Confederation College maintained transparency about the ongoing investigation, publicly stating that if forensic analysis revealed compromised personal data, affected individuals would receive direct notification. The incident response prioritized determining whether data theft occurred alongside restoring operational systems. No details were provided about the malware variant involved, initial intrusion vectors, or exact duration of service interruptions beyond the weekend timeframe. The college's public communications focused on the absence of confirmed data compromise at that stage while acknowledging the seriousness of the disruption. Technology teams continued working with external investigators to establish definitive findings about potential information exposure stemming from the security event.

Sources

Sources available to members: 1 source.

CSIDB