The Federation of Sovereign Indigenous Nations paid more than $20,000 to an anonymous hacker who breached its computer system.
The hacker gained control of the FSIN's internal files and email system.
A wide range of data was taken which included files on residential school survivors, youth athletes and their coaches, internal land claims and a host of other topics like social insurance numbers, treaty card numbers
Source: https://www.cbc.ca/news/canada/saskatoon/fsin-hacked-bitcoin-payment-data-breach-1.4875487
TPRM report: https://www.rankiteo.com/company/federation-of-sovereign-indigenous-nations
"id": "fed2211291022",
"linkid": "federation-of-sovereign-indigenous-nations",
"type": "Breach",
"date": "6/2017",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Indigenous Affairs',
'name': 'Federation of Sovereign Indigenous Nations',
'type': 'Non-profit Organization'}],
'attack_vector': 'Compromised Internal Systems',
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': ['Social insurance '
'numbers',
'Treaty card numbers'],
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personal Information',
'Sensitive Documents']},
'description': 'The Federation of Sovereign Indigenous Nations (FSIN) '
'experienced a cyber incident where an anonymous hacker gained '
'control of its internal files and email system. The incident '
'involved data exfiltration and a ransom demand.',
'impact': {'data_compromised': ['Residential school survivors',
'Youth athletes and their coaches',
'Internal land claims',
'Social insurance numbers',
'Treaty card numbers'],
'financial_loss': 'More than $20,000',
'identity_theft_risk': 'High',
'systems_affected': ['Internal files', 'Email system']},
'motivation': 'Financial Gain',
'ransomware': {'data_exfiltration': 'Yes',
'ransom_demanded': 'More than $20,000',
'ransom_paid': 'More than $20,000'},
'threat_actor': 'Anonymous Hacker',
'title': 'FSIN Data Breach and Ransomware Attack',
'type': 'Data Breach and Ransomware'}