Canada's tax agency and UK parenting site Mumsnet are the first confirmed victims of Heartbleed

Himanshu Arora

Posts: 902   +7
Staff

Just a few days after the Canada Revenue Agency (CRA) blocked public access to its online services due to concerns over the Heartbleed bug, the agency has confirmed that prior to the preventive measure, an attacker exploited the bug and removed social insurance numbers of approximately 900 taxpayers from the agency's systems, according to a BBC report.

"Regrettably, the CRA has been notified by the Government of Canada's lead security agencies of a malicious breach of taxpayer data that occurred over a six-hour period," the agency said. The Privacy Commissioner of Canada has been informed of the incident, and the Royal Canadian Mounted Police has started the investigation.

CRA commissioner Andrew Treusch said that the taxpayers who are affected by the breach will receive notification of the incident via registered letter rather than email, in order to avoid giving criminals a chance to exploit the situation, and will be given access to free credit protection services.

Aside from the CRA, the UK parenting site Mumsnet also announced that its data has been stolen by hackers exploiting the Heartbleed bug. Founder Justine Roberts told the BBC that the attackers could have made off with potentially all login details.

Roberts said she came to know about the attack after her own login credentials were compromised by the attackers, who then informed the website admins that the attack was related to Heartbleed. The website is now forcing all its members to reset any password created on or before Saturday.

Permalink to story.

 
Confirmed? How?

The Canada Revenue Agency refuses to provide any details...even though the RCMP claim they have a suspect.
 
Pretty small leak.... in canada only 900 SINs.. 900 too many but not bad
 
A 6 hour period ? The 6 hours after the news was released to the public and every wannabe hacker in the world went holy moly short window to sploitz me some data for the sheer giggle of it. Thanks media for the heads up...

Ya know like all the papers are like, oh change ya passwords now. So, most numptys probably did that without checking that the website had updated encryption or not... on top of that those who did check that said website had updated their encryption then thought "yay safe" and logged into their unsafe email boxes to click on their confirmation of changed password emails.

You gotta love the mass media panic. Best thing to do would have been reboot the interwebs at head office and during the downtime fix the ssl leak that was apparently made by some german, who only confessed all once someone shouted blame towards the NSA and general nazi communist American direction. Who then rang up Hans Upitwasme ... and begged him to take the blame for a percentage of earnings to come directly from the "windows xp support tax fund paid by country tax payers who love to get fudged over funds".

Gotta hate this world we live in.
 
Back