HomeSecurityOPSEU hit by 'cybersecurity incident,' unclear if data compromised, it says

OPSEU hit by ‘cybersecurity incident,’ unclear if data compromised, it says

OPSEU hit by ‘cybersecurity incident,’ unclear if data compromised, it says

Date:

A union that represents public sector workers in Ontario says it was hit by a “cybersecurity incident” on Wednesday but it cannot say what data, if any, was compromised by the attack.

The Ontario Public Service Employees Union (OPSEU), which has 180,000 members across the province, said an investigation has begun into the attack, which was reported to members on Thursday.

“All signs point to this being an attack by sophisticated actors,” Kelsea Mahabir, spokesperson for OPSEU, said in an email on Friday.

Mahabir said the incident was not a failure of the union’s IT teams or systems. 

“Upon discovering the incident, we immediately implemented countermeasures to contain the incident and engaged third-party cybersecurity experts to assist with containment, remediation and to conduct a thorough investigation to assess the cause and extent of this incident.”

If the investigation finds any personal information was impacted, OPSEU says it will notify those affected “promptly.”

On Sunday, Mahabir said the union had regained access to its communication tools and was in the process of restoring its servers. 

“We’re getting closer to a return to normal,” Mahabir said in an email.  

In a message on its website, dated Thursday, the union blamed an “unauthorized third party” for accessing its IT systems.

“Our investigation is still in its early stages. We are conducting a thorough review and validation of our systems as part of this incident and are gradually bringing them back online,” the union said in the message.

The union added that it is working with outside lawyers and the police, and its members should expect disruptions to normal operations.

It encouraged members to monitor their financial accounts and contact their banks immediately if they notice any suspicious activity. Members are also urged to be cautious of “unsolicited communications that request personal information” or that direct them to a web page asking for such information.

Toronto police directed all questions about the incident to the union.

Image by Freepik

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Share post:

spot_imgspot_img

Popular

More like this
Related

Third-Party Cyber Risk Emerges as the Weakest Link in 2026

The World Economic Forum’s Outlook 2026 shows cyber risk entering organizations through suppliers, SaaS vendors, logistics providers, and technology partners.

56% of CEOs are Still Not Seeing ROI from AI Investments in 2026

PwC’s CEO Survey reveals why many organizations struggle to see ROI from AI, highlighting adoption gaps, integration challenges, and vendor implications

50% of Companies to Raise Supply Chain Tech Budgets in 2026: APQC

Demand planning, forecasting, AI-enabled planning models, and automation are now central to executive discussions.

Shadow AI Is the New AI Security Risk. Here’s How to Get Ahead of It.

“Most organizations today have shadow AI — they just...