Rainbow District School Board: SINs, bank accounts likely compromised in Ontario school board cyber incident

Rainbow District School Board: SINs, bank accounts likely compromised in Ontario school board cyber incident

Rainbow District School Board Reports Data Breach Affecting Employees and Students

The Rainbow District School Board, serving schools in Sudbury, Espanola, and Manitoulin Island, disclosed a cyber incident on February 7 that likely compromised sensitive personal and financial data. While no confirmed cases of fraud have been reported, the breach exposed information for current and former employees, students, and voters.

Impacted Groups and Compromised Data:

  • Former employees (2005–2009, not rehired after 2010): Social Insurance Numbers (SINs).
  • Current/former employees (2002): Bank account numbers, employee IDs, addresses, and annual salaries.
  • Benefits enrollees (2009, 2016): Beneficiary names and phone numbers.
  • Employees with criminal record checks (2012–2019): Same as above.
  • Students (1966–2024): Dates of birth, Ontario Education Numbers, and grades.
  • 2022 municipal election voters (Greater Sudbury): Dates of birth and addresses.

The board engaged a third-party expert to investigate the breach, concluding its assessment nine months later. The incident was reported to Ontario’s Information and Privacy Commissioner, with the board emphasizing its commitment to transparency and accountability. Affected individuals include full-time, part-time, and occasional staff.

Source: https://globalnews.ca/news/11579784/rainbow-district-school-board-cyber-incident/

Rainbow Schools cybersecurity rating report: https://www.rankiteo.com/company/rainbowschools

"id": "RAI1765922881",
"linkid": "rainbowschools",
"type": "Breach",
"date": "2/2025",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 'Current and former employees, '
                                              'students, and voters in the '
                                              '2022 municipal election',
                        'industry': 'Education',
                        'location': 'Sudbury, Espanola, Manitoulin Island, '
                                    'Ontario, Canada',
                        'name': 'Rainbow District School Board',
                        'type': 'School Board'}],
 'customer_advisories': "Public notice on the board's website",
 'data_breach': {'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (personally identifiable and '
                                        'financial information)',
                 'type_of_data_compromised': ['Social Insurance Numbers (SINs)',
                                              'Bank account information',
                                              'Employee IDs',
                                              'Addresses',
                                              'Annual salaries',
                                              'Beneficiary names',
                                              'Phone numbers',
                                              'Dates of birth',
                                              'Student Ontario Education '
                                              'Numbers',
                                              'Grades']},
 'date_detected': '2024-02-07',
 'date_publicly_disclosed': '2024-10-28',
 'description': 'A cyber incident at the Rainbow District School Board in '
                'northern Ontario likely compromised employee social insurance '
                'numbers and bank account information. The incident occurred '
                'on February 7, 2024, and impacted current and former '
                'employees, students, and voters in the 2022 municipal '
                'election.',
 'impact': {'brand_reputation_impact': 'Likely negative impact on trust and '
                                       'transparency',
            'data_compromised': 'Social insurance numbers, bank account '
                                'information, employee IDs, addresses, annual '
                                'salaries, beneficiary names, phone numbers, '
                                'dates of birth, Student Ontario Education '
                                'Numbers, grades',
            'identity_theft_risk': 'High (due to compromised SINs and personal '
                                   'data)',
            'payment_information_risk': 'High (due to compromised bank account '
                                        'information)'},
 'investigation_status': 'Ongoing (as of October 2024)',
 'references': [{'date_accessed': '2024-10-28',
                 'source': 'Rainbow District School Board Website'},
                {'date_accessed': '2024-10-28', 'source': 'Global News'}],
 'regulatory_compliance': {'regulatory_notifications': 'Reported to the '
                                                       'Information and '
                                                       'Privacy Commissioner '
                                                       'of Ontario'},
 'response': {'communication_strategy': "Public notice on the board's website "
                                        'and reporting to the Information and '
                                        'Privacy Commissioner of Ontario',
              'third_party_assistance': 'Hired a third-party expert to '
                                        'investigate the incident'},
 'title': 'Rainbow District School Board Cyber Incident',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.