Skip links

Toronto Zoo ransomware crooks snatch decades of visitor data

Toronto Zoo’s final update on its January 2024 cyberattack arrived this week, revealing that visitor data going back to 2000 had been compromised.

It said everyone who purchased a general admission ticket or zoo membership between 2000 and April 2023 had their personal data stolen by ransomware crooks in the digital heist.

First and last names were stolen, as were home addresses, phone numbers, and email addresses “in some records.” For those who made credit card transactions between January 2022 and April 2023, card details such as the last four digits of the number and expiration dates were also lifted.

“Phishing and online fraud is ever present today,” the update reads. “We encourage those affected and all our guests and members to be vigilant, and to carefully examine uninvited and suspicious communications and to regularly check financial account statements.

“Your Toronto Zoo has reported this matter to the Office of the Information and Privacy Commissioner of Ontario (the IPC) and an investigation file has been opened. The IPC has advised that it is not necessary for you to file a complaint as they are already investigating the matter.”

Per a recent press release, the zoo said it attracts around 1.2 million visitors each year, and as of 2023, around 35,000 households were part of its membership program.

Toronto Zoo also briefly summarized its previous updates, noting that in addition to 23 years’ worth of visitor and member data being stolen, all current and former staff members going back to 1989 had their details compromised, too.

Each person was informed about this last year and was offered an apology and the usual credit monitoring services.

The zoo didn’t mention the word “ransomware” anywhere in the final communication about its attack, although it has done so in the past, and to refresh the memory, the break in was the work of ransomware outfit Akira.

Over a year later, Akira still has the zoo’s data available to download and claims all 133 GB of it consists of NDAs, personal files, “and of course, lots of interesting info about animals.”

Planting its roots in 2023, Akira rose to prominence last year after claiming major scalps like Lush, Tietoevry, Stanford University, and Nissan Australia. By June, experts were telling The Register that it could be the next big thing in ransomware after law enforcement had their way with BlackCat and LockBit, the former dominant players.

Toronto Zoo’s final words on the matter were somber and regretful over the data stolen, but assured its defenses were now thoroughly shored up.

“This cyber incident has been extremely challenging for us, particularly our current and past employees who had personal information compromised but also due to the loss of decades of wildlife conservation research that was lost as well.

“Since this incident, we have taken significant steps to ensure our information technology is more secure and have been working closely with the City of Toronto’s Chief Information Security Office and we are grateful for their expertise and ongoing support. Our enhancements will give us significantly better network defenses and better ability to detect security problems.”

Finally, the zoo thanked its supporters for sticking with it throughout the past year: “We would also like to express our heartfelt gratitude to our employees, volunteers, Zoo members, guests, and our community supporters for their patience and understanding as we worked through this challenge together.” ®

Source