To say that the London Drugs chain is a fixture in western Canada is probably an understatement. With some 79 stores, along with affiliated businesses (such as grocery chain IGA, executive jet service London Air, and technology supplies wholesaler TLD) the company touches a wide slice of everyday life in this part of the world. 

No wonder it came as a bit of a shock to many to find out one morning that the entire London Drugs chain had shut its doors. Initially there was little background. The first tweet from the chain’s X/Twitter account referred to an “operational issue” and the need for stores to be closed until further notice.

Canadians have become somewhat used to the terms “cybersecurity incident” and “cyberattack.” Why London Drugs was reluctant to use that term from the get-go is not clear. After all, we’ve heard of the LifeLabs cyberattack, as well as the one on Indigo/Chapters, to name but a couple of similar events.

A day later, “operational issue” had become “cybersecurity incident,” at which point most experts in such matters were muttering the term “ransomware.” BC Business in a 2023 story estimated $3 billion in sales for the previous year for the London Drugs chain. In rough terms that comes down to around $100,000 per day per store. Using eight days as a measure of most stores being closed this means sales losses on the order of $800,000 per store, or around $65 million across the chain.

Of course those are sales losses, which don’t take into account the costs incurred as third parties were engaged to restore the back end computer systems to the point where stores could reopen. Interestingly, according to some reports, London Drugs continued to pay all its personnel while stores were closed to the public.

London Drugs social media post advising the public about the cyberattack that shuttered the chain for days. 

Most cybersecurity firms suggest cyberattacks have increased in the past several years. Ransomware attacks are particularly prevalent and profitable as they stampede a business into making a financial response in order to regain control of its systems.

At one time U.S. law enforcement recommended American business victims of ransomware attacks should pay up in order to get their data restored as there was little likelihood of successful enforcement action, and certainly next to no chance of restoring the data once encrypted without cooperation of the perpetrators. This is no longer the case.

For London Drugs, the chain’s store operations were clearly impacted. Eventually the company also shut down its phone system. In the short term the company kept its pharmacies running, but only for emergency needs and through in-person visits once the phones were shut down.

Presumably there were also impacts on customers who used the chain’s post office outlets. Perhaps outgoing mail was able to ship but it is not clear if incoming parcel deliveries were affected.

Interestingly, on social media most comments were quite conciliatory towards London Drugs. The “it’s not a matter of if, but a matter of when” in reference to a cyberattack seems to have been taken to heart by the broader community. I saw one post where the writer was so taken aback by the attack that he suggested he’d be giving back all his rewards points to the chain once operations were restored. Others noted the positive work environment at London Drugs, pointing out that their favourite store had employees with decades of service.

In a report by Canadian legal firm Blakes, entitled Canadian Cybersecurity Trends 2023, the note is made that some 860 Canadian public companies made cybersecurity-related incident disclosures in 2023. In more than two-thirds of cases, company data (which presumably included customer data) was accessed, and in about the same fraction of cases a ransom was paid.

How much do ransomware attacks cost? We really don’t know in most cases. Indigo said it spent more than $5 million to restore its operations. This figure does not include the loss of business while its stores were closed.

Writing on LinkedIn in response to a comment that a particular security product might have protected the London Drugs IT infrastructure, Chester Wisniewski, Director, Global Field CTO at Sophos, said: “If only it were that easy. No product is perfect and with human adversaries a successful defense requires a lot of things to be perfectly in place. In the end, they (London Drugs) are victims and I wish their IT and security teams all the best on a quick return to normal. I can’t even imagine the stress they are under at the moment.”

Once the entire London Drugs chain had reopened, president and chief operating officer Clint Mahlman appeared on various news outlets and also wrote a lengthy email to members of the company’s customer points program. Although no mention was made of the term “ransomware,” Mahlman did refer twice in an on-air interview with Simi Sara of CKNW to “threat actors.”

Generally speaking this “threat actor” term has come to refer to highly organized, and in some cases state-sponsored groups (think North Korea, China, Russia) that specialize in collecting ransomware payments from medium to large-sized business operations.

Just after the London Drugs incident I received a cybersecurity advisory from the Federal Bureau of Investigation, the Cybersecurity and Infrastructure Security Agency, the Department of Health and Human Services, and the Multi-State Information Sharing and Analysis Center in the United States. This advisory carried extensive background on Black Basta, a group thought to have attacked around 500 companies and organizations across the world.

Here’s part of the advisory: “Black Basta affiliates use common initial access techniques—such as phishing and exploiting known vulnerabilities—and then employ a double-extortion model, both encrypting systems and exfiltrating data. Ransom notes do not generally include an initial ransom demand or payment instructions. Instead, the notes provide victims with a unique code and instructs them to contact the ransomware group via a .onion URL (reachable through the Tor browser). Typically, the ransom notes give victims between 10 and 12 days to pay the ransom before the ransomware group publishes their data on the Black Basta TOR site, Basta News.”

As this column went to press, there came news that the B.C. government has experienced a cybersecurity incident of some sort, with details unclear. Whether there is connection to the London Drugs shutdown, or to Black Basta, is unknown, but it seems clear these sorts of events are here to stay for the foreseeable future.

Follow me on Facebook (facebook.com/PeterVogelCA), or on Twitter (@PeterVogel)

pvogel@outlook.com