Cyber Incident Victim: Confederation College
Date:
Feb 2020
Location:
Canada
Summary
Confederation College experienced a malware incident that disrupted numerous online services, prompting an investigation by technology staff and external cybersecurity experts. While the institution confirmed no evidence of unauthorized access or exfiltration of student personal information during the initial assessment, a forensic review remains ongoing to definitively assess potential data compromise. The college committed to directly notifying affected individuals if the investigation reveals any personal information was removed.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 3 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In late January or early February 2020, Confederation College experienced a malware incident that disrupted many of its online services over a weekend. Technology staff initiated an investigation into a potential security breach following the service outages. The disruption impacted core digital operations, though the specific systems affected were not detailed publicly. College personnel worked to restore functionality while assessing whether the malware incident resulted in unauthorized access to sensitive information. At the time of reporting on February 1, no evidence had been found indicating exfiltration of student personal information. The institution engaged external cybersecurity experts to conduct a forensic examination of the incident to determine its full scope and nature.

Confederation College maintained transparency about the ongoing investigation, publicly stating that if forensic analysis revealed compromised personal data, affected individuals would receive direct notification. The incident response prioritized determining whether data theft occurred alongside restoring operational systems. No details were provided about the malware variant involved, initial intrusion vectors, or exact duration of service interruptions beyond the weekend timeframe. The college's public communications focused on the absence of confirmed data compromise at that stage while acknowledging the seriousness of the disruption. Technology teams continued working with external investigators to establish definitive findings about potential information exposure stemming from the security event.
