Canadian school photo company says hackers held Sask. students' pictures for ransom
A Canadian school photography company says it was hit by a ransomware attack that held about 3,500 photos of students in several Saskatchewan school divisions hostage, among others across the country.
On Feb. 15, Edge Imaging contacted the office of the privacy commissioner to disclose a “cyber incident that may have affected school divisions across Canada,” according to a report released last week.
In a letter to the commission, Edge Imaging said the breach affected Entourage, the owner of its yearbook software web platform Creator Studio Pro, after the service noticed a breach of its Canadian Amazon Web Services cloud server “that may have affected uploaded images of school boards’ students and staff.
“On February 5, 2024, Entourage recognized a cyber incident on its cloud server due to a compromised username and password of one of its server accounts. The result was a ransomware attack where the threat actor removed photo images on a storage container on that server,” Edge wrote to Ron Kruzeniski, Saskatchewan’s privacy commissioner.
“We are advised by Entourage that the photos were ‘raw’ and likely contained no other identifying information such as associated names, schools, grades, location, or captions. Entourage recently commented that there may have been some metadata associated with the photos depending on the device from which the photos were uploaded. For instance, it is possible that metadata such as time the photo was taken and location of the photo may have been attached to some photos.”
According to Kruzeniski, just over 3,500 images of Saskatchewan students and staff were held ransom by the hackers, affecting people in the Horizon, Living Sky and Prairie Spirit school divisions.
In total, about 400 of the photography company’s clients were affected by the ransomware attack. The largest cache of photos stolen in Saskatchewan came from schools in Muenster and St. Brieux.
Edge, the Canadian photography company, said the attack was limited to its yearbook software service provider Entourage, and did not affect its own internal IT.
Edge told Kruzeniski’s office the images involved in the hack included a lot of candid photos of school events and clubs.
“Schools often upload photos of clubs, events or candid photos that are often included in a yearbook,” Edge told the commission. “Where we are the school photography provider, we do upload photos from the school photography sessions.”
Photos taken by Edge Imaging would have very limited metadata attached, but photos uploaded directly by schools for use in the yearbook, such as those captured by students and parents, could have more detailed information in the metadata, depending on the settings of each individual’s camera, the company said.
In his report, Kruzeniski writes that it’s possible the people in the photos could be identified.
“It is likely that some of the images as described by the school divisions and Edge, if not all, could lead to the identification of the individuals on them based on factors such as race, ethnic origin, age, appearance in a certain location, etc. This would then reveal information that is personal in nature about an identifiable individual. Based on this, I find that there is personal information involved.”
Many of the stolen files were later recovered by Entourage, Kruzeniski says, but given that his office has worked on cases where stolen data was found for sale on the dark web years later, “there are no assurances that the breach was fully contained.”
To read about the school divisions’ response to the privacy breach and Kruzeniski’s recommendations to prevent future breaches, read the full report here.
CTVNews.ca Top Stories
BREAKING Canadian rapper K'naan charged with sexual assault following arrest in Quebec City
Canadian singer K’naan has been charged with sexual assault after being arrested by police in Quebec City.
WATCH LIVE Helene is upgraded to Category 2 hurricane, threatens 'unsurvivable' storm surge as it barrels toward Florida
Fast-moving Hurricane Helene was advancing Thursday across the Gulf of Mexico toward Florida, threatening a 'catastrophic' storm surge in northwestern parts of the state as well as damaging winds, rains and flash floods hundreds of kilometres inland across much of the southeastern U.S., forecasters said.
DEVELOPING Feds charge NYC mayor with selling his influence to foreign nationals. He says he won't quit
New York City Mayor Eric Adams was indicted Thursday on charges that he took illegal campaign contributions and bribes from foreign nationals, including lavish overseas trips, in exchange for favors that included helping Turkish officials bypass a fire inspection for a new diplomatic tower in the city.
Coyote snatches dog from backyard of Tommy Lee, wife Brittany Furlan; she grabs beloved pet back
A terrifying coyote attack was caught on camera at the San Fernando Valley home of rocker Tommy Lee and his wife Brittany Furlan.
Tempted to switch to an online-only bank? Know the perks and drawbacks
Switching to an online-only bank more than a decade ago was just another way Jessica Morgan was trying to save money at the time as a new grad.
Canada and allies call for immediate 21-day ceasefire between Lebanon and Israel
Canada has issued a joint statement with its allies calling for 'an immediate 21-day ceasefire across the Lebanon-Israel border,' citing an 'unacceptable risk of a broader regional escalation.'
Oklahoma executes a man for a 1992 killing despite board recommending his life be spared
Oklahoma was preparing to execute a man Thursday while waiting for Republican Gov. Kevin Stitt to decide whether to spare the death row inmate's life and accept a rare clemency recommendation from the state's parole board.
Canada's new limits on temporary foreign workers start today. Here's an overview
New changes to Canada's temporary foreign worker program are now in effect. Here's what to know.
NASA downplays role in development of Titan submersible that imploded
OceanGate co-founder Stockton Rush said the carbon fibre hull used in an experimental submersible that imploded en route to the wreckage of the Titanic was developed with help of NASA and aerospace manufacturers, but a NASA official testified Thursday that the space agency actually had little involvement at all.