Industry Insights

Blog, Technology

‘We’re sorry’: 15M LifeLabs customers may have had data breached in cyberattack

by | Wednesday, December 18th, 2019

LifeLabs, one of the largest private providers of health diagnostic testing, said in an open letter to its customers that the firm had become aware of a recent hack to its computer systems that contained customer information, names and logins. It didn’t specify exactly who had hacked the system but LifeLabs alerted the Ontario and B.C. privacy commissioners of the hack on Nov. 1. LifeLabs also said it paid a ransom to secure the data. LifeLabs’ letter also said the majority of these customers were in Ontario and British Columbia, with “relatively few customers” in other locations. LifeLabs President and CEO Charles Brown told CTV News approximately 10 million affected were in Ontario, with five million in B.C. When it came to lab results, LifeLabs said the hack affected 85,000 of its Ontario customers from 2016 or earlier.“Our investigation to date indicates any instance of health care information was from 2016 or earlier,” the letter added.
The firm discovered the cyberattack in late October and Brown has since personally apologized for the hack.
“I’d like to say to our customers that we’re sorry. We realize this may have shaken their confidence and we’ll do everything we can to win it back,” he told CTV News. “We know that health data is important and we do take that responsibility quite seriously.”

LIFELABS CAN’T GUARANTEE DATA WASN’T COPIED

In the letter, Brown said that the risk to customers from the data breach was low. He also said cybersecurity firms told them they hadn’t seen a public disclosure of the customer data online, including on the dark web or other online locations. Following the advice of cybersecurity experts, he said they retrieved “the data by making a payment,” Brown said. He later explained his thinking behind that decision.

“Our desire was to try to get this data and keep it as secure as we could and not have it exposed,” he told CTV News.

But LifeLabs couldn’t guarantee that the hackers were unable to save a copy of the data. The firm has also been in touch with law enforcement, its government partners and notified privacy commissioners.

According to a joint statement from the Information and Privacy Commissioner for British Columbia and the Information and Privacy Commissioner of Ontario, LifeLabs had reported the hack to them on Nov. 1 and said that the hackers had been demanding a ransom.

Cybersecurity expert Brian O’Higgins told CTV News Channel customers “may have dodged a bullet” since the hackers were likely more interested in obtaining money in exchange for people’s personal data rather than caring about the lab results.

But the fact the hackers have any personal information at all could lead to identity theft and “that could lead to a world of hurt.”

The privacy commissioners’ co-ordinated investigation will examine the extent of the breach, what led up to it and what – if anything — could have been done to prevent it.

“An attack of this scale is extremely troubling. I know it will be very distressing to those who may have been affected. This should serve as a reminder to all institutions, large and small, to be vigilant,” Information and Privacy Commissioner of Ontario Brian Beamish said in the statement.

Information and Privacy Commissioner for B.C. Michael McEvoy added,  “our independent offices are committed to thoroughly investigating this breach. We will publicly report our findings and recommendations once our work is complete.”

LIFELABS HAS TO DO BETTER: FMR. PRIVACY OFFICIAL

Former Information and Privacy Commissioner of Ontario Ann Cavoukian told CTV News Channel the hack is “very damaging.”

Despite LifeLabs saying it paid the ransom, there are no guarantees the data won’t show up elsewhere. Cavoukian said it’s “virtually impossible to control in terms of getting it back and you don’t know where it might appear.”

She said once customers give up their personal data to third parties, they’re at their mercy. That’s why she chastised Lifelabs for not having strong enough security to prevent the data from being stolen.

“I say that data at rest (such as the health card numbers and addresses) should be strongly encrypted so it doesn’t serve as a magnet for the bad guys,” Cavoukian said. “You don’t want to be an easy target. And that’s what’s so appalling. LifeLabs should have had the strongest security measures in place already.”

She said the bulk “of responsibility of the protection of this data is with LifeLabs.” Going forward, LifeLabs CEO pledged the company will strengthen its system to deter future hacks.

LifeLabs said it is offering “any customer who is concerned about this incident” a free year of protection including dark web monitoring and identity theft insurance from American consumer credit reporting agency TransUnion.

But Cavoukian argued that it’s also on the consumer to contact LifeLabs directly to ask if their data has been compromised. She also predicted there could be class-action lawsuits following the breach.

 

See here for the original CTV article.

A Glimpse Into What Compliance Looks Like for Businesses

It’s easy to see all the reasons why you should make data regulations and compliance a priority. After all, you want to ensure you don’t violate the trust and security of your customers, as well as the integrity of your operations. If you make even one mistake, it...

AI Search Isn’t There Yet

People do this all the time: if they don’t know an answer, they just make something up that sounds right. It turns out AI has the same bad habit. A Study Put AI Search to the Test, and It Did Not Go Well Researchers at the Tow Center for Digital Journalism (part of...

Remote Work Is Great, but There Are Some Pitfalls

Do you have employees working remotely? If you do, the real question is, are you doing everything you can to keep them productive and secure? Remote work is awesome, but it comes with its fair share of risks. Today, we get into how to competently confront them. Remote...

Hiring IT is Hard (Here’s How to Make It Easier)

Do you have someone on your staff who can handle most IT-related issues for your business? If not, we’re sure your organization feels it in more ways than one. The issues that come from not having IT help are only made more frustrating when it comes time to find IT...

Let’s Take the Lid Off of CAPTCHA

We've officially reached the point where humans have to prove they're, well, human just to access websites. One of the most common ways to do this? CAPTCHA. CAPTCHA stands for Completely Automated Public Turing test to tell Computers and Humans Apart. It might sound...

Automation Isn’t Always the Best Business Option

Automation makes sense from an operations standpoint, and people see this despite the many who advocate for scaling back to save jobs. For every task that can be completed, however, less than half can be automated. When you consider all the tasks that a human might be...

More Reading from Industry Insights:

AI Search Isn’t There Yet

People do this all the time: if they don’t know an answer, they just make something up that sounds right. It turns out AI has the same bad habit. A Study Put AI Search to the Test, and It Did Not Go Well Researchers at the Tow Center for Digital Journalism (part of...

Hiring IT is Hard (Here’s How to Make It Easier)

Do you have someone on your staff who can handle most IT-related issues for your business? If not, we’re sure your organization feels it in more ways than one. The issues that come from not having IT help are only made more frustrating when it comes time to find IT...