Data leak
Bell Canada / CBC / The Globe and Mail
Primary Source βIncident Details
An unnamed hacker breached Bell Canada in May 2017 and exfiltrated data on approximately 1.9 million active and former customer accounts, including names, email addresses, phone numbers, and usernames. The attacker threatened to release the data publicly unless Bell Canada lobbied against upcoming Canadian internet regulations. Bell refused and the hacker published a portion of the data (approximately 3 GB). Bell confirmed the breach on May 15 2017 and stated no financial data, Social Insurance Numbers, or passwords were accessed. This was a separate and distinct incident from the 2014 NullCrew SQL injection breach, despite a similar record count.
Technical Details
- Initial Attack Vector
- CWE-284: Improper Access Control (unauthorised access to Bell systems by an unnamed hacker who threatened to release data unless Bell lobbied against Canadian internet regulation)
Timeline
- 2017-05-01 Breach occurred
- 2017-05-15 Publicly disclosed
- 2017-05-15 Customers notified