Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Quebec Ministry of Cybersecurity and Digital Technology employee data leaked (journaldemontreal.com)
33 points by matbilodeau on Aug 3, 2023 | hide | past | favorite | 22 comments


We love la belle langue but HN is an English language site so articles here need to be in English. If there's a suitable URL covering the same story, we can update it.

https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...


can't do much , didn't make English language news. Google translate seems to have problems with some news sites. Here's what Radio-Canada (french CBC) has to say

https://ici.radio-canada.ca/nouvelle/2001279/incident-securi...

The Ministère de la Cybersécurité et du Numérique du Québec confirmed on Thursday that an incident of computer security due to an action by an employee was quickly corrected.

This employee has been transferred to une boîte de courriel personale des documents contenant des renseignements personnels de 529 employés de la fonction publique. Elle aurait agi de bonne foi et a collaboré avec le ministère, a indicé ce dernier en réponse aux questions de Radio-Canada.

The incident occurred on May 23 last year, when the employee was transferred to another public organization. She explained that she had transferred documents to be able to answer the questions of her replacement in order to facilitate the transition.

The ministry specified that the employee had access to this information in the framework of his duties.

Even if the intention of the employee was not to use the information for an illegal purpose, this practice contravenes the rules of safety in place intended for the personnel of MCN, the ministry emphasized in its email to Radio-Canada.

Par ailleurs, the ministère indicated that a complaint had been filed with the police so that an inquiry could be opened.

The employee was also sanctioned for not respecting the rules of the ministry, which ensured the destruction of the information transferred to the personal email box.

The Information Access Commission was also informed of the incident.


Translation / TLDR

Former HR employee (compensation) exfiltrated data to their personal email address. data included first and last name , SIN numbers of ministry employees. No evidence of wrongdoing yet but it raises questions of gross incompetence coming from the ministry in charge of preventing data loss.


I worked for a company with a few thousand employees.

HR had laptops with employee data on it stolen 3 times in two years. Each time they had left the laptop in their car after work when they went out to eat.

That, among other things is my long sad experience with HR.

It’s always some rando in a department / job where the rules don’t matter it seems.


I believe HR is commonly targeted by attackers, precisely because they have access to sensitive personal information on their employees. I used to work at a company where a high-level HR employee received an email purporting to be from the CEO, asking for a list of all employees and SSN's. Rather than asking critical questions about this request, they simply collected the requested information into a spreadsheet and emailed it to the attacker. Presumably all of our information was subsequently sold to identity thieves.


Seems more likely that it was just a random laptop theft rather than a targeted SSN capture


Let me guess, also a non-encrypted disk ?


It is the old fashioned 'who guards the guards'. Eventually, someone does have access to all sorts of 'not good' things. Here, it is only surprising that it was HR.


Once we had a system that allowed notifications on employee changes, and an admin who ticked a fun box that resulted in everybody with an email on their employee profile getting notified in plaintext on SSN changes with before and after values.

Many processes on the payroll vendor's side and our company were changed after that day.


This is the Quebec government, it doesn't get any more grossly incompetent. The only question is what took so long


Please keep regional flamewar off HN.

https://news.ycombinator.com/newsguidelines.html


I think that that comment is being misinterpreted.

It doesn't seem to me to be an attempt at inciting a "regional flamewar".

The sentiment it describes is quite strongly held by people from and in that region, especially by those who've unfortunately experienced it first-hand for themselves.


That's a reasonable point, but most people (or at least many people) in $region are going to interpret such a comment as a regional attack even if it wasn't intended that way. Most people's identity has something to do with where they live.


> it doesn't get any more grossly incompetent

Unless you are referring to tech in particular, that seems very harsh. The ministry of digital transformation is a shitshow, but the governement itself has not done anything that would warrant the label "grossly incompetent".


I beg to disagree. It's hard to imagine handling the education and health portfolios worse than this provincial government has.


Quebec has the best life expectancy in the americas. It's PISA scores are above the canadian average, which is itself close to best in the whole world.


It's easy to imagine for those who've lived in provinces under an NDP government.


Um, healthcare, infrastructure... being completely absorbed in racism and anti Anglo hysteria, the GP comment is to nice if anything


The QC government isn't the worst, but their prospects have been scary for someone like me.

I'd rather not be a second class citizen for being raised with the "wrong language".


Obviously you're not a taxpayer here


(nit) Title has typo, should be "Ministry"


thanks, I actually copy pasted the title (Minister of...) since I couldn't find the actual name in English on the govt. website.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: