A Caisse populaire Desjardins sign is seen in Montreal on Tuesday, June 18, 2019. The federal privacy watchdog says a series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest in the Canadian financial services sector. THE CANADIAN PRESS/Paul Chiasson

A Caisse populaire Desjardins sign is seen in Montreal on Tuesday, June 18, 2019. The federal privacy watchdog says a series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest in the Canadian financial services sector. THE CANADIAN PRESS/Paul Chiasson

Series of gaps allowed massive Desjardins data breach, privacy watchdog says

The incident compromised the data of nearly 9.7 million Canadians

A series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest to date in the Canadian financial services sector, the federal privacy watchdog has found.

In a report today, privacy commissioner Daniel Therrien said Desjardins did not demonstrate the level of attention needed to protect the sensitive personal information entrusted to its care.

The incident compromised the data of nearly 9.7 million Canadians.

“Canadians expect banking information to have a high level of protection, given its sensitivity,” Therrien told a news conference today.

For at least 26 months, a malicious employee was siphoning sensitive personal information collected by Desjardins from customers who had purchased or received products through the organization, Therrien found.

This information was originally stored in two data warehouses to which the employee in question had limited access, the commissioner said.

However, other employees, in the course of fulfilling their work, would regularly copy that information onto a shared drive. As a result, employees who would not usually have the required clearance or the need to access some of the confidential data were able to do so, Therrien found.

The commissioner says the investigation into the breach sheds light on the risks of internal threats, whether they are intentional or not.

The investigation revealed that Desjardins failed to meet several of its obligations under the federal privacy law governing companies. Therrien found:

  • Desjardins did not ensure proper implementation of its policies and procedures for managing personal information, some of which were inadequate;
  • The access controls and data segregation of the company’s databases and directories were lacking;
  • Employee training and awareness were inadequate, considering the sensitive nature of the personal information;
  • Desjardins did not have proper procedures regarding the periodic destruction of personal information.

Desjardins agreed to a series of recommendations to improve information security and the protection of personal data, Therrien said.

The company has committed to provide progress reports every six months as well as hire external auditors to assess and certify its programs.

Therrien’s office and the Commission d’accès à l’information du Québec, which also published its report today, co-ordinated their respective probes.

Jim Bronskill, The Canadian Press

Like us on Facebook and follow us on Twitter.

Want to support local journalism? Make a donation here.

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

A man sustained burns to his body near this spot around 3:30 a.m. Tuesday, April 13 in Courtenay. The fire was left of the pathway. The Station youth housing facility and city public works yard are to the right of the trail. Photo by Terry Farrell
Emergency personnel respond to man on fire in wooded area of Courtenay

A man was badly burned in the early morning hours Tuesday in… Continue reading

This 2013 Dodge Ram 1500 was stolen from Black Creek Motors at approximately 2 a.m. Sunday, April 11. Photos via blackcreekmotors.com
VIDEO: Thieves steal truck from Black Creek car lot by towing it away

Have you seen a 2013 Dodge Ram 1500 in your neighbourhood in… Continue reading

Teresa Hedley and a copy of her book, “What’s Not Allowed? A Family Journey with Autism.” Photo supplied
Comox Library recognizes Autism Awareness Month with presentation by local author

April is World Autism Awareness Month, an annual opportunity to increase understanding… Continue reading

Comox council will further look at a troublesome traffic area in the Point Holmes area of the town. Photo submitted
Comox council to look at speed calming measures at Point Holmes

“…We are waiting for a problem to happen if we don’t act.”

A 41-person air task force, including 12 members from 407 Long Range Patrol Squadron at 19 Wing Comox, seized more than $3 million CND worth of cocaine as part of Op Caribbe. Photo by Canadian Armed Forces Operations/Facebook
19 Wing Comox crew involved in three-tonne cocaine seizure worth more than $293 million

12 members from 407 Long Range Patrol Squadron involved in Op Caribbe

Restaurant patrons enjoy the weather on a patio in Vancouver, B.C., Monday, April 5, 2021. The province has restricted indoor dining at all restaurants in B.C. due to a spike in COVID-19 numbers. THE CANADIAN PRESS/Jonathan Hayward
B.C.’s COVID-19 indoor dining, drinking ban extending into May

Restaurant association says patio rules to be clarified

Cannabis bought in British Columbia (Ashley Wadhwani/Black Press Media)
Is it time to start thinking about greener ways to package cannabis?

Packaging suppliers are still figuring eco-friendly and affordable packaging options that fit the mandates of Cannabis Regulations

Two men were seen removing red dresses alongside the Island Highway in Oyster Bay. (Submitted photo)
Two men filmed removing red dresses from trees on highway near Ladysmith

Activists hung the dresses to raise awareness for Vancouver Island’s Murdered/Missing Women & Girls

Comox Lake is the drinking water source for the CVRD. Photo supplied
Comox Valley Water Treatment Project nears completion

The Comox Valley Water Treatment Project is more than 85 per cent… Continue reading

B.C. Premier John Horgan speaks at the B.C. legislature. (B.C. government)
Tougher COVID-19 restrictions in B.C., including travel, still ‘on the table’: Horgan

John Horgan says travel restrictions will be discussed Wednesday by the provincial cabinet

RCMP on scene yesterday at the altercation at the trailer park. (Submitted photo)
Violent altercation at Port Hardy trailer park sends one to hospital

Police say man confronted another over airsoft shooting, then was attacked with a weapon

Comox council approved a change in fees for using the Comox Municipal Marina, extending the collection of fees from March 1 to Oct. 31 each year. Black Press file photo
Fee changes, increased costs coming to Comox Municipal Marina

The town will be extending the collection of fees from March 1 to Oct. 31

John Albert Buchanan was found guilty of manslaughter in the 2017 death of Richard Sitar. Pictured here, Buchanan walking to the court in Nanaimo last year. (Karl Yu/News Bulletin)
Six years including time served for Nanaimo man in bludgeoning death

John Albert Buchanan sentenced in B.C. Supreme Court in Nanaimo for death of Richard Sitar

Protesters occupied a road leading to Fairy Creek Watershed near Port Renfrew. (Submitted photo)
B.C. First Nation says logging activist interference not welcome at Fairy Creek

Vancouver Island’s Pacheedaht concerned about increasing polarization over forestry activities

Most Read