A Caisse populaire Desjardins sign is seen in Montreal on Tuesday, June 18, 2019. The federal privacy watchdog says a series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest in the Canadian financial services sector. THE CANADIAN PRESS/Paul Chiasson

A Caisse populaire Desjardins sign is seen in Montreal on Tuesday, June 18, 2019. The federal privacy watchdog says a series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest in the Canadian financial services sector. THE CANADIAN PRESS/Paul Chiasson

Series of gaps allowed massive Desjardins data breach, privacy watchdog says

The incident compromised the data of nearly 9.7 million Canadians

A series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest to date in the Canadian financial services sector, the federal privacy watchdog has found.

In a report today, privacy commissioner Daniel Therrien said Desjardins did not demonstrate the level of attention needed to protect the sensitive personal information entrusted to its care.

The incident compromised the data of nearly 9.7 million Canadians.

“Canadians expect banking information to have a high level of protection, given its sensitivity,” Therrien told a news conference today.

For at least 26 months, a malicious employee was siphoning sensitive personal information collected by Desjardins from customers who had purchased or received products through the organization, Therrien found.

This information was originally stored in two data warehouses to which the employee in question had limited access, the commissioner said.

However, other employees, in the course of fulfilling their work, would regularly copy that information onto a shared drive. As a result, employees who would not usually have the required clearance or the need to access some of the confidential data were able to do so, Therrien found.

The commissioner says the investigation into the breach sheds light on the risks of internal threats, whether they are intentional or not.

The investigation revealed that Desjardins failed to meet several of its obligations under the federal privacy law governing companies. Therrien found:

  • Desjardins did not ensure proper implementation of its policies and procedures for managing personal information, some of which were inadequate;
  • The access controls and data segregation of the company’s databases and directories were lacking;
  • Employee training and awareness were inadequate, considering the sensitive nature of the personal information;
  • Desjardins did not have proper procedures regarding the periodic destruction of personal information.

Desjardins agreed to a series of recommendations to improve information security and the protection of personal data, Therrien said.

The company has committed to provide progress reports every six months as well as hire external auditors to assess and certify its programs.

Therrien’s office and the Commission d’accès à l’information du Québec, which also published its report today, co-ordinated their respective probes.

Jim Bronskill, The Canadian Press

Like us on Facebook and follow us on Twitter.

Want to support local journalism? Make a donation here.

Just Posted

A nurse gets a swab ready to perform a test on a patient at a drive-in COVID-19 clinic in Montreal, on Wednesday, October 21, 2020. THE CANADIAN PRESS/Paul Chiasson
Island’s daily COVID-19 case count drops below 10 for just the second time in 2021

Province reports 8 new COVID-19 cases on Vancouver Island Wednesday

Island Health’s new Wellness and Recovery Centre at 5878 York Rd. is now planned to be open in the fall. (File photo)
Wellness and Recovery Centre now to open in the fall

Three community dialogues scheduled for May

Before you take on a pet, make sure you want to have it for life. (Sarah Simpson/Citizen)
Editorial: A pet is a lifetime commitment

Tons of people are getting pets during the pandemic, some for the first time

Over 60 Indigenous youth from Qualicum to Malahat are participating in the Step Up Work Placement Program. (Submitted photo)
New Mid-Island Indigenous youth work placement program seeks employer partners

So far, more than 60 youth from Qualicum Beach to the Malahat are participating in the program

Sign of the times: this property on View Street in Chemainus that exp Realty’s Debbie Simmonds had listed at $599,000 sold for $650,000. (Photo by Don Bodger)
Real estate market continues to soar in the Chemainus area

Multiple offers on properties common, leading to sales above listing prices

Marc Kielburger, screen left, and Craig Kielburger, screen right, appear as witnesses via video conference during a House of Commons finance committee in the Wellington Building in Ottawa on Tuesday, July 28, 2020. The committee is looking into Government Spending, WE Charity and the Canada Student Service Grant. THE CANADIAN PRESS/Sean Kilpatrick
BREAKING: Trudeau didn’t violate conflict rules over WE Charity, watchdog says

Federal ethics commissioner Mario Dion found that former finance minister Bill Morneau did violate the rules

Commissioner Austin Cullen listens to introductions before opening statements at the Cullen Commission of Inquiry into Money Laundering in British Columbia in Vancouver. THE CANADIAN PRESS/Darryl Dyck
B.C. money laundering inquiry could have lessons for other provinces: lawyer

4 reports concluded the flow of hundreds of millions of dollars in illegal cash linked to organized crime and the drug trade impacted the province’s real estate, luxury vehicle and gaming sectors

Pixabay
Island Health: two doctors, new clinic space to avert Port McNeill health crisis

Island Health has leased space to use as an immediate clinic location to avert health crisis

Cannabis bought in British Columbia (Ashley Wadhwani/Black Press Media)
Is it time to start thinking about greener ways to package cannabis?

Packaging suppliers are still figuring eco-friendly and affordable packaging options that fit the mandates of Cannabis Regulations

Police investigate a fatal 2011 shooting in a strip mall across from Central City Shopping Centre, which was deemed a gang hit. The Mayor’s Gang Task Force zeroed in on ways to reduce gang involvement and activity. (File photo)
COVID-19 could be a cause in public nature of B.C. gang violence: expert

Martin Bouchard says the pandemic has changed people’s routines and they aren’t getting out of their homes often, which could play a role in the brazen nature of shootings

A poignant Pandemic Postcard Project submission has led Lesley Wright and Graham Hughes of Literacy Alberni on a new path toward anti-racism education. (SUSAN QUINN/ Alberni Valley News)
‘I am not a virus’: How one postcard sparked a Vancouver Island pushback against racism

Literacy Alberni receives $50K in funding to create web-driven system for reporting racism

Tinder, an online dating application that allows users to anonymously swipe to like or dislike other’s profiles. (Black Press Media files)
B.C. man granted paternity test to see if Tinder match-up led to a ‘beautiful baby’

The plaintiff is seeking contact with the married woman’s infant who he believes is his child

Nurse Tami Arnold prepares to administer a COVID-19 vaccine. (Kareem Elgazzar/AP)
B.C. adults 30+ now eligible to get vaccinated against COVID-19

Health officials made the announcement Wednesday afternoon

Ancient Forest Alliance campaigner Andrea Inness walks beside an enormous western red cedar stump in a BCTS-issued cutblock in the Nahmint Valley. (PHOTO COURTESY TJ WATT)
Watchdog: logging practices put Vancouver Island old growth, biodiversity at risk

Forest Practices Board has issues with BC Timber Sales practices in Nahmint Valley near Port Alberni

Most Read