Close Alert Banner
Close Old Browser Notification
Browser Compatibility Notification
It appears you are trying to access this site using an outdated browser. As a result, parts of the site may not function properly for you. We recommend updating your browser to its most recent version at your earliest convenience.
Skip to Content
Region of Durham Logo
Contact Us
Engage
  • Living Here
    • 211 – Connect with local community services
    • 311 – Connecting you to our services
    • A to Z Services
    • Accessibility
    • Age-Friendly Durham
    • Animal Services and Control
    • Child Care and Early Years
    • Climate, Energy and Resilience
    • Conservation Authorities
    • Counselling
    • Crime Prevention and Public Safety
    • Durham Employment Services
    • Education and Schools
    • Emergency Preparedness
    • Emergency Services
    • Emergency Social Services
    • Garbage and Recycling
    • Housing and Homelessness
    • Libraries
    • View More...
    View our Garbage and Recycling page

    Garbage and Recycling

    View our My Property page

    My Property

    View our Roads and Traffic page

    Roads and Traffic

  • Discovering Durham
    • About Durham Region
    • Arts and Culture
    • Bike Month
    • Cycling and Walking
    • E-mobility
    • Local Food and Farmers' Markets
    • Maps
    • New to Durham Region
    • Parks, Trails and Conservation Areas
    • Spectator Sports
    • Sport Tourism
    • Sports and Recreation
    • Tourism
    • Tourism Festival and Events Calendar
    • Transportation and Transit
    View our Tourism page

    Tourism

    View our Tourism Festival and Events calendar

    Tourism Festival and Events Calendar

    View our Transportation and Transit page

    Transportation and Transit

  • Doing Business
    • Applications, Licences and Permits
    • As-Built Drawing Request
    • Bid Opportunities
    • Business Directory
    • Business Count
    • Community Social Investment Program
    • Construction and Your Business
    • Construction Liens
    • Design and Construction Specifications
    • Economic Development
    • Events
    • Funding Resources
    • Garbage and Recycling Collection on Private Property
    • Housing
    • Municipal Consent
    • Operating a Child Care Centre
    • Planning and Development
    • Public Health and Your Business
    • Purchasing
    • View More...
    View our Agriculture page

    Agriculture

    View our Business Directory page

    Business Directory

    View our Purchasing page

    Purchasing

  • Health and Wellness
    • Alcohol, Cannabis, Drugs and Smoking
    • Babies and Toddlers
    • Child Health and School-Age Children
    • Clinics and Classes Calendar
    • COVID-19
    • Domestic Violence
    • Dental and Oral Health
    • Environment and Your Health
    • Food and Eating
    • Health Care Professionals
    • Health Check-Up! Reports and Health Plans
    • Health Information Services
    • Healthy Living
    • Illness, Infection and Disease
    • Immunizations and Vaccines
    • Injury Prevention and Safety
    • Mental Health
    • Pregnancy
    • Public Health Inspections and Investigations
    • View More...
    View our Health Care Professionals page

    Health Care Professionals

    Launch the Durham Region Respiratory Virus Data Tracker

    Respiratory Virus Data Tracker

    Report Immunizations Online

    Report Immunizations Online

  • Regional Government
    • A to Z Services
    • Access to Information
    • Accountability and Transparency
    • Advocacy Priorities
    • Awards
    • Budget and Financial
    • By-Laws
    • Careers and Volunteering
    • CityStudio Durham
    • Community Engagement
    • Community Safety and Well-Being Plan
    • Contact Us
    • Court and Traffic Tickets (Provincial Offences)
    • Departments
    • Diversity, Equity and Inclusion
    • Durham Region 101
    • Durham Region Strategic Plan
    • Durham Works
    • Innovation
    • View More...
    View our Council page

    Council

    View our Open Data page

    Open Data

    View our Regional Services map

    Regional Services

I'd Like To...

Apply or Register For

  • Applications, Licences and Permits
  • Bidding Opportunities
  • Careers and Volunteering
  • Freedom of Information Request
  • Housing

Learn About

  • A to Z Services
  • Being New to Durham Region
  • Budget
  • By-Laws
  • Council
  • Durham Region Transit
  • Public Health Inspections

Report an Issue

  • By-Law Infraction
  • Downed Sign
  • Health Protection Complaint
  • Illegal Dumping
  • Missed Garbage or Recycling Pickup
View our X Page View our Facebook Page View our YouTube Page view our LinkedIn page

Region head office.

CyberSecurity

Decrease text size Default text size Increase text size
Print this page
Share this page
  • Facebook
  • LinkedIn
  • Twitter
  • Email

Cybersecurity incident with third-party software provider, impacts Durham Region

Last update: 2021-10-21  11:36 AM

If you believe you are the victim of a cyber crime, you should report it to the police.
To learn more visit the Durham Regional Police Service (DRPS) website.

FAQs

The following information only applies to residents who received a notification letter about the cybersecurity incident with the third-party software provider in 2021.

Q: What happened?
The Regional Municipality of Durham was impacted by a cybersecurity incident that occurred with a third-party software provider used by the Region.
Q: What are you doing about it?

We took prompt steps to contain the incident. Our IT team, working with the service provider, took immediate steps to secure our systems. The vulnerability related to the service provider has been addressed.

We have stopped using the third party software involved.

We have notified individuals who may have been impacted by this incident and are in contact with the relevant authorities and regulators as part of the process.

Q: What was the impact?
This incident impacted a very small portion of the overall data managed by the Region.
Q: Who was the third-party software provider?
We are unable to share details of third-party providers used by the Region.
Q: When did this happen?

Based on our investigation, the cybersecurity incident occurred on or around January 20, 2021.

Q: When did you first know about it?

We became aware of the incident on March 25, 2021.

Q: How do I know if I’m affected by this?

We have notified individuals who may have been impacted by this incident. If you fall into this category, you will receive a letter from us. 

Q: How do I know what types of my data may have been impacted?

If you receive a letter, it will indicate what type of data may have been impacted.

Q: I’ve received a letter. Does this mean that someone has my information? What can I do to check? 

If you have received a letter from Durham Region about this issue, then it is possible your information may have been impacted by this incident. 

There is no evidence confirming that all the personal information listed in the letter was compromised or misused, although the unauthorized third party posted some of the documents containing personal information and personal health information on the dark web in April 2021.

If you are contacted and advised that your health card number may have been affected by the incident, you can call the ServiceOntario INFOline at 1-866-532-3161 or 1-800-387-5559 to report any lost or stolen health card number.

Individuals who suspect misuse of their health card number can report suspected cases of fraud by emailing the Ontario Ministry of Health at reportOHIPfraud@moh.gov.on.ca or by calling 1-888-781-5556.

For instances where financial information may have been impacted, we are offering credit monitoring to those individuals.

If you are contacted and advised that your financial information may have been affected by the incident, as a precautionary measure, we strongly suggest  that you contact your bank, credit card company, and relevant government offices to advise them that you may have been affected by this incident.

We recommend you monitor and verify all your bank accounts, credit card and other financial transaction statements for any suspicious activity. If you suspect misuse of your personal information, you can obtain a copy of your credit report from a credit reporting bureau to verify the legitimacy of the transactions listed.

  • Equifax at 1-800-465-7166 or equifax.ca
  • TransUnion at 1-800-663-9980 or transunion.ca

If you are concerned that you may be a victim of fraud, you may request these bureaus place a fraud alert on your credit files instructing creditors to contact you before opening any new accounts. You may also wish to review this publication from the Information and Privacy Commissioner of Ontario, Identity Theft: A Crime of Opportunity.

For tips and resources for protecting your identity please visit ontario.ca/page/how-avoid-or-recover-identity-theft.

We are committed to protecting the personal information in our care and we are taking this matter very seriously. We are sorry for the inconvenience this may cause.

Q: Why is the Region disclosing this now? 

We have been working with our experts to determine the full extent of the information that may be involved and provided an initial update on our investigation through a statement on our website on April 9, 2021.

At this stage, we know an unauthorized third party accessed some personal information and we are currently notifying individuals directly who may have been impacted by this incident. We sent our first letters to those potentially impacted the week commencing April 19, 2021, and updated our FAQ and statement on our website the same day.

We are also in contact with the relevant authorities and regulators as part of the process.

Q. I believe or suspect that my information is being misused. What are you going to do about it?

Please contact our call centre at 1-833-526-0566 with any details that you can share about any suspected misuse of your information such as timing, nature of the data, where you suspect the misuse to be occurring.

We will keep this on file and are recording this information as part of our investigation. If you have any concerns, we urge you to visit https://www.ontario.ca/page/how-avoid-or-recover-identity-theft. 

Q: I am concerned about identity theft. What can I do to protect myself?

It is important to note that there is no evidence to date showing that the data involved in the incident was misused.

For tips and resources for protecting your identity please visit ontario.ca/page/how-avoid-or-recover-identity-theft

Q: Have you contacted police?

Yes, we notified law enforcement.

Q: Why does Durham Region hold my data?

Our partners collect personal information on our behalf and the data is used to carry out the Region’s responsibilities. The Region has an obligation to collect this information. We rigorously follow data retention policies to minimize the vulnerability. 

This data collection is governed by legislation including the Immunization of School Pupils Act, Child Care and Early Years Act, 2014, and the Ambulance Act.

It is important to note that there is no evidence to date showing that the data involved in the incident was misused.

Q: I’ve received a letter saying some of my health data may have been impacted. Why does the Region have my health data?
There are different categories of health information that may have been impacted, and the notification letters sent are specific to the circumstances of those individuals. See the description below for the category relevant to you, as noted in your letter.
  • Oral Health - we collect a small amount of oral health information related to clients receiving dental procedures.
  • Child Care - we collect child care data as part of the Child Care and Early Years Act, 2014 to ensure children have appropriate immunizations. This is a standard process when a child is signed up to CCC. Parents fill out a form when they enroll in a child care centre and this is sent to the Region.
  • Seniors’ Care - we have information related to staff of long-term care homes, retirement homes and other congregant living facilities related to immunization eligibility. Earlier in the COVID-19 vaccination efforts, we were relaying information about vaccine eligibility to appropriate health authorities.
  • School Boards - we have student and parent/guardian information under the Immunization of School Pupils Act. This information is required to maintain up-to-date immunization records.

Q: Has the investigation been completed?

Durham Region has completed its investigation into this incident. We have identified and notified all individuals who may have been impacted. 

The Ontario Information and Privacy Commissioner (IPC) concluded its review of Durham Region’s privacy breach on Jan. 18, 2022. 

Q: What were the results of the investigation?

Durham Region has completed its investigation into the cybersecurity incident. All individuals who may have been impacted have been notified. The Region has taken the necessary actions to strengthen our cybersecurity safeguards.

With regards to our IT systems - the vulnerability related to the service provider has been addressed, and our systems have been secured. We also perform privacy risk assessments for any software we use.

We notified the proper authorities and regulators as part of the investigation. The Ontario Information and Privacy Commissioner (IPC) concluded its review of Durham Region’s privacy breach on Jan. 18, 2022.

We are committed to protecting the privacy of all residents and are taking this matter very seriously. 

Q: I have more questions. Can I speak to anybody about this?

Please contact our dedicated call centre at 1-833-526-0566. Hours of operation are Monday to Friday, from 9 a.m. to 4:30 p.m. ET.

 

Statement

Last update: 2021-04-20  10:59 AM

On March 25, 2021, The Regional Municipality of Durham became aware of a cybersecurity incident that occurred with a third-party software provider used by the Region.

Our IT teams, working with the service provider, took immediate steps to secure our systems. The vulnerability related to the service provider has been addressed, and our systems have been secured.

Our experts are diligently investigating the matter, and we are in contact with the relevant authorities and regulators as part of the process.

Although the investigation is ongoing, based on what we know at this stage, we believe that an unauthorized third party accessed some personal information. The information included some health, financial and/or other personal information.

We are notifying individuals directly who may have been impacted by this incident.

If you are contacted and advised that your health card number may have been affected by the incident, you can call the ServiceOntario INFOline at 1-866-532-3161 or 1-800-387-5559 to report any lost or stolen health card number. Individuals who suspect misuse of their health card number can report suspected cases of fraud by emailing the Ontario Ministry of Health at ReportOHIPfraud@moh.gov.on.ca or by calling 1-888-781-5556.

If you are contacted and advised that your financial information may have been affected by the incident, as a precautionary measure, we strongly suggest that you contact your bank, credit card company, and relevant government offices to advise them that you may have been affected by this incident.

We recommend you monitor and verify all your bank accounts, credit card and other financial transaction statements for any suspicious activity. If you suspect misuse of your personal information, you can obtain a copy of your credit report from a credit reporting bureau to verify the legitimacy of the transactions listed.

  • Equifax at 1-800-465-7166 or equifax.ca
  • TransUnion at 1-800-663-9980 or transunion.ca

If you are concerned that you may be a victim of fraud, you may request these bureaus place a fraud alert on your credit files instructing creditors to contact you before opening any new accounts. You may also wish to review this publication from the Information and Privacy Commissioner of Ontario, Identity Theft: A Crime of Opportunity.

We are committed to protecting the privacy of all residents and we are taking this matter very seriously. We are sorry for the inconvenience this may have caused.

 

Media Statement

Statement from The Regional Municipality of Durham
Issued: 2021-04-09

The Regional Municipality of Durham recently became aware of a cybersecurity incident that occurred with a third-party software provider, which impacted the Region.

We have contacted the relevant authorities and regulators. Our IT teams, working with the service provider, took immediate steps to secure our systems. The incident did not impact the Region’s core IT systems.

Our experts are now investigating the matter to determine the information that may be involved and the impact of this incident. It is important to note that the vulnerability related to the service provider has been addressed and our systems have been secured.

We are committed to protecting the privacy of all residents and we are taking this matter very seriously. We are sorry for the inconvenience this may cause affected parties.

Receive email updates

Contact Us

Region of Durham logo

Living HereDiscovering DurhamDoing BusinessHealth and WellnessRegional Government

© 2025 Durham Region, 605 Rossland Road East, Whitby, Ontario L1N 6A3, Canada, Telephone (within regional limits): 311, Telephone: 905-668-7711, Toll-Free: 1-800-372-1102

Terms of UsePrivacyCareersA to Z ServicesContact UsSitemap
By GHD Digital