A Caisse populaire Desjardins sign is seen in Montreal on Tuesday, June 18, 2019. The federal privacy watchdog says a series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest in the Canadian financial services sector. THE CANADIAN PRESS/Paul Chiasson

A Caisse populaire Desjardins sign is seen in Montreal on Tuesday, June 18, 2019. The federal privacy watchdog says a series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest in the Canadian financial services sector. THE CANADIAN PRESS/Paul Chiasson

Series of gaps allowed massive Desjardins data breach, privacy watchdog says

The incident compromised the data of nearly 9.7 million Canadians

A series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest to date in the Canadian financial services sector, the federal privacy watchdog has found.

In a report today, privacy commissioner Daniel Therrien said Desjardins did not demonstrate the level of attention needed to protect the sensitive personal information entrusted to its care.

The incident compromised the data of nearly 9.7 million Canadians.

“Canadians expect banking information to have a high level of protection, given its sensitivity,” Therrien told a news conference today.

For at least 26 months, a malicious employee was siphoning sensitive personal information collected by Desjardins from customers who had purchased or received products through the organization, Therrien found.

This information was originally stored in two data warehouses to which the employee in question had limited access, the commissioner said.

However, other employees, in the course of fulfilling their work, would regularly copy that information onto a shared drive. As a result, employees who would not usually have the required clearance or the need to access some of the confidential data were able to do so, Therrien found.

The commissioner says the investigation into the breach sheds light on the risks of internal threats, whether they are intentional or not.

The investigation revealed that Desjardins failed to meet several of its obligations under the federal privacy law governing companies. Therrien found:

  • Desjardins did not ensure proper implementation of its policies and procedures for managing personal information, some of which were inadequate;
  • The access controls and data segregation of the company’s databases and directories were lacking;
  • Employee training and awareness were inadequate, considering the sensitive nature of the personal information;
  • Desjardins did not have proper procedures regarding the periodic destruction of personal information.

Desjardins agreed to a series of recommendations to improve information security and the protection of personal data, Therrien said.

The company has committed to provide progress reports every six months as well as hire external auditors to assess and certify its programs.

Therrien’s office and the Commission d’accès à l’information du Québec, which also published its report today, co-ordinated their respective probes.

Jim Bronskill, The Canadian Press

Like us on Facebook and follow us on Twitter.

Want to support local journalism? Make a donation here.

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

Alberta has 3,651 active cases of COVID-19.  (File photo)
750 new COVID-19 cases identified in Alberta Sunday

Central zone currently has 1,182 active cases of the virus

county
County of Paintearth highlights from Jan. 12th

County graders have been out blading ice at intersections where ice buildup has been bad

The Pfizer-BioNTech vaccine deliveres to Canada are being delayed because of complications at their European distribution facility. THE CANADIAN PRESS/Nathan Denette
Delays of Pfizer vaccine delivery to impact Alberta’s vaccination plans

Alberta has administered 74,000 doses of the COVID-19 vaccine so far

ski
Valley Ski Club Slope Stabilization Project is awarded CFEP Grant

With forecasts predicting continued mild weather, the board made the decision not to proceed with the current season

A scene from “Canada and the Gulf War: In their own words,” a video by The Memory Project, a program of Historica Canada, is shown in this undated illustration. THE CANADIAN PRESS/HO - Historica Canada
New video marks Canada’s contributions to first Gulf War on 30th anniversary

Veterans Affairs Canada says around 4,500 Canadian military personnel served during the war

Conservative Leader Erin O’Toole holds a press conference on Parliament Hill, in Ottawa on December 10, 2020. THE CANADIAN PRESS/Sean Kilpatrick
No place for ‘far right’ in Conservative Party, Erin O’Toole says

O’Toole condemned the Capitol attack as ‘horrifying’ and sought to distance himself and the Tories from Trumpism

A passer by walks in High Park, in Toronto, Thursday, Jan. 14, 2021. This workweek will kick off with what’s fabled to be the most depressing day of the year, during one of the darkest eras in recent history. THE CANADIAN PRESS/Chris Young
‘Blue Monday’ getting you down? Exercise may be the cure, say experts

Many jurisdictions are tightening restrictions to curb soaring COVID-19 case counts

A health-care worker prepares a dose of the Pfizer-BioNTech COVID-19 vaccine at a UHN COVID-19 vaccine clinic in Toronto on Thursday, January 7, 2021. THE CANADIAN PRESS/Nathan Denette
COVID-19: Provinces work on revised plans as Pfizer-BioNTech shipments to slow down

Anita Anand said she understands and shares Canadians’ concerns about the drug company’s decision

Prime Minister Justin Trudeau listens to a question during a news conference outside Rideau cottage in Ottawa, Friday, January 8, 2021. THE CANADIAN PRESS/Adrian Wyld
Trudeau says Canada’s COVID vaccine plan on track despite Pfizer cutting back deliveries

Canadian officials say country will still likely receive four million doses by the end of March

(Via the Canadian Press)
Alberta monolith comes with message to save eastern slopes of Rocky Mountains

‘They deserve our attention. They warrant our protection. They are under threat’

blessing
Bentley Blessing Pantry continues to faithfully serve the community

‘We just wanted to make everyone aware that we are still here to serve you throughout this coming year.’

A Suncor logo is shown at the company’s annual meeting in Calgary on May 2, 2019. A worker is missing after a dozer broke through ice on an inactive Suncor tailings pond in northern Alberta.THE CANADIAN PRESS/Jeff McIntosh
Worker missing after dozer breaks through frozen tailings pond in northern Alberta

The worker was an employee of Christina River Construction

File Photo
‘You took away some real joy,’ Sylvan Lake Winter Village turned off after vandalism

Sometime during the night of Jan, 12 the light display at the pier was vandalized and damaged

Most Read