Lifelabs. Add another name to the ignominious pantheon occupied by the likes of Capital One, Equifax, and Desjardins. And this one may be the biggest of all here in Canada.

This was to be a retrospective column but as the year grew to a close a name we only associate with occasional trips to a clinic for a blood test suddenly became front and centre in TV newscasts, radio broadcasts, and newspapers.

One of the major private components of health care in this province, Lifelabs provides testing and diagnostic services in primarily B.C. and Ontario. It bills this province around a quarter of a million dollars a year.

Lifelabs, which acquired long-established B.C. Biomedical to become the dominant player in the diagnostic specimens domain, also controls myeHealth, an online portal that provides B.C. residents with rapid access to their test results. 

As such, Lifelabs is the repository for a significant volume of data, including most British Columbians – around five million current and deceased B.C. residents – and 10 million or so Ontarians. 

When news broke Dec. 17 that Lifelabs had fallen prey to a cyberattack, there was naturally concern from anyone who had been a customer. What exactly transpired? What potential consequences might there be? Why was a company managing such extensive and sensitive data not using the best possible safeguards and techniques to keep personal information from the clutches of hackers?

Answers to these questions may be a long time coming, but rest assured the privacy commissioners of both provinces are demanding them.

What we know is that somehow Lifelabs customer data became encrypted by ransomware on or about the last day of October. Within 48 hours B.C. Health Minister Adrian Dix was notified. He and the company agreed to keep the matter under wraps for almost seven weeks, a delay that the minister said was needed to give the company time to retrieve the data and to ensure no other data was at risk.

We know, at least according to the company, that the access records of all 15 million Lifelabs customers were rendered inaccessible after the company was hit with a ransomware attack. We don’t know whether it was through a spearphishing email that targeted, say, a Lifelabs executive with access to the user database, or through hackers snooping around and then locking up the database. 

Until recently, ransomware attacks were mostly delivered blindly through emails; click on a payload link and bingo, a user’s data became inaccessible until a ransom was paid. Wanting to preserve a lucrative business model, the hackers more often than not deliver an unlock code after the ransom is paid.

However, some of the hacking gangs have become more specialized, taking copies of sensitive data and ratcheting up the ransom pressure by threatening to publish such data. 

We don’t know how the Lifelabs hack occurred but we do know a threat was made to publish some data. It may be that this threat centred on the actual test results of 85,000 Ontario residents. The rest of the ransomed data consisted of names, health card numbers, dates of birth, user names, and passwords for either the Lifelabs website or the myeHealth web site.

No less an organization than the FBI has recommended that businesses seeking to recover ransomed data go ahead and pay up. This naturally goes against intuition that negotiating with kidnappers, for instance, leads to more kidnappings.

How much did Lifelabs pay to regain access to its customer data? We may never know. Initially I mused that it may have been around 50 BTC (Bitcoin), worth roughly US $300,000 on Dec. 17. However, if the hackers were aware of the nature of the data they held, 1000 BTC is not out of the question.

In the days after the data compromise became public knowledge, Lifelabs CEO Charles Brown did not exactly engender trust in his governance or in the company itself when he indicated in a radio interview with the CBC’s Stephen Quinn that he simply did not know if customer data was stored in an encrypted form.

Needless to say the company has become a magnet for social media attacks. One of the more entertaining tweets referenced LifeLabs’ statement that the decision to pay the ransom was made “in collaboration with experts familiar with cyber-attacks and negotiations with cyber criminals.”

Tweeted @jpreseme, “Did you make the payment with Apple iTunes cards, or did it go through a guy who said he was calling from the CRA?”

Knowing that your customer data at Lifelabs has been compromised, what do you do? At the very least, take advantage of the free credit and security monitoring the company has set up with TransUnion. Phone 1-888-918-0467, select option 2, and get your 12-letter code. Go to mytrueidentity.ca, enter the code, and follow the prompts. You will see your credit score, along with tabs for a credit report and identity protection insurance amounts.

Although Lifelabs states in its public notice about the security breach that “the risk to our customers in connection with this cyber-attack is low,” it is difficult to support such a conjecture until the true nature of the attack is known.

If indeed the data was locally encrypted and rendered unusable by an email-based infection, then it may well be that the risk of any additional fallout is low. If, however, attackers were able to roam around, undetected initially, they may well have grabbed a copy of the database before encrypting the company’s copy.

Meanwhile, the myeHealth site continues to implausibly claim that the company uses “a variety of secure technologies and procedures to help protect your information from unauthorized access, use or disclosure.”

Follow me on Facebook (facebook.com/PeterVogelCA), on Twitter (@PeterVogel), or on Instagram (@plvogel) 

pvogel@outlook.com