Other

Rogers Communications Network Outage / Breach β€” 12 Million Canadians Disrupted

πŸ“… 2022-07-08 🏒 Rogers Communications network infrastructure
Primary Source β†—

Incident Details

On 8 July 2022, Rogers Communications β€” Canada’s largest telecommunications company serving approximately 12 million wireless customers β€” suffered a massive network outage that lasted approximately 16 hours for most customers, with some services taking days to fully restore. The outage was caused by a maintenance update to core network routers that triggered a cascade failure. While not a cyberattack, the outage had severe cyber-incident-like impacts: emergency 911 services were disrupted across multiple provinces, bank ATMs and point-of-sale terminals failed, hospitals lost communications, and police and emergency services were affected. The Canadian Radio-television and Telecommunications Commission (CRTC) opened an investigation. Rogers’ CEO Tony Staffieri subsequently stated the outage stemmed from a coding error during a network maintenance update. The CRTC found that Rogers had failed to maintain adequate network resiliency. Rogers and Telus had an interconnection agreement for emergency 911 backup that was not triggered. The outage highlighted Canada’s dependence on a small number of national telecommunications carriers and the catastrophic risk of network configuration errors at scale. Rogers paid affected customers a total of approximately $150 million in credits. The CRTC subsequently mandated emergency network backup agreements between major carriers. The incident prompted federal legislation requiring telecoms to file incident response plans.

Technical Details

Initial Attack Vector
A network maintenance update to Rogers' IP routing policy distributed during a network upgrade caused a cascade failure across Rogers' core network; the failure was a configuration error rather than a cyberattack; the outage took down mobile, internet, and cable services for approximately 12 million Canadian customers
Vendor / Product
Rogers Communications network infrastructure

Timeline

  1. 2022-07-08 Breach occurred
  2. 2022-07-08 Publicly disclosed
  3. 2022-07-08 Customers notified