A Caisse populaire Desjardins sign is seen in Montreal on Tuesday, June 18, 2019. The federal privacy watchdog says a series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest in the Canadian financial services sector. THE CANADIAN PRESS/Paul Chiasson

A Caisse populaire Desjardins sign is seen in Montreal on Tuesday, June 18, 2019. The federal privacy watchdog says a series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest in the Canadian financial services sector. THE CANADIAN PRESS/Paul Chiasson

Series of gaps allowed massive Desjardins data breach, privacy watchdog says

The incident compromised the data of nearly 9.7 million Canadians

A series of technological and administrative gaps caused a high-profile data breach at Desjardins — the largest to date in the Canadian financial services sector, the federal privacy watchdog has found.

In a report today, privacy commissioner Daniel Therrien said Desjardins did not demonstrate the level of attention needed to protect the sensitive personal information entrusted to its care.

The incident compromised the data of nearly 9.7 million Canadians.

“Canadians expect banking information to have a high level of protection, given its sensitivity,” Therrien told a news conference today.

For at least 26 months, a malicious employee was siphoning sensitive personal information collected by Desjardins from customers who had purchased or received products through the organization, Therrien found.

This information was originally stored in two data warehouses to which the employee in question had limited access, the commissioner said.

However, other employees, in the course of fulfilling their work, would regularly copy that information onto a shared drive. As a result, employees who would not usually have the required clearance or the need to access some of the confidential data were able to do so, Therrien found.

The commissioner says the investigation into the breach sheds light on the risks of internal threats, whether they are intentional or not.

The investigation revealed that Desjardins failed to meet several of its obligations under the federal privacy law governing companies. Therrien found:

  • Desjardins did not ensure proper implementation of its policies and procedures for managing personal information, some of which were inadequate;
  • The access controls and data segregation of the company’s databases and directories were lacking;
  • Employee training and awareness were inadequate, considering the sensitive nature of the personal information;
  • Desjardins did not have proper procedures regarding the periodic destruction of personal information.

Desjardins agreed to a series of recommendations to improve information security and the protection of personal data, Therrien said.

The company has committed to provide progress reports every six months as well as hire external auditors to assess and certify its programs.

Therrien’s office and the Commission d’accès à l’information du Québec, which also published its report today, co-ordinated their respective probes.

Jim Bronskill, The Canadian Press

Like us on Facebook and follow us on Twitter.

Want to support local journalism? Make a donation here.

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

Terry Keogh, an RDN Transit driver, used his paramedic skills the morning of Jan. 22 after coming across an unconscious woman along his route in downtown Nanaimo. (RDN Transit photo)
RDN Transit driver stops his bus and helps get overdosing woman breathing again

Former EMT from Ireland performed CPR on a woman in downtown Nanaimo on Friday

The intersection at Moilliet Street and Despard Avenue where a 12-year-old boy was struck by an oncoming vehicle early November while crossing at a marked crosswalk. (Mandy Moraes photo)
City staff members, school district officials to discuss high-traffic Parksville intersection

Young boy suffered broken leg after being hit in Despard/Moilliet crossing

U.S. Senator Bernie Sanders sits in on a COVID-19 briefing with Dr. Bonnie Henry, provincial health officer, and Adrian Dix, B.C. minister of health. (Birinder Narang/Twitter)
PHOTOS: Bernie Sanders visits B.C. landmarks through the magic of photo editing

Residents jump on viral trend of photoshopping U.S. senator into images

Nanaimo Regional General Hospital. (News Bulletin file photo)
COVID-19 outbreak declared at Nanaimo hospital

Two staff members and one patient have tested positive, all on the same floor

A long-term care worker receives the Pfizer vaccine at a clinic in Nanaimo earlier this month. (Island Health photo)
All Island seniors in long-term care will be vaccinated by the end of this weekend

Immunization of high-risk population will continue over the next two months

A 75-year-old aircraft has been languishing in a parking lot on the campus of the University of the Fraser Valley, but will soon be moved to the B.C. Aviation Museum. (Paul Henderson/ Chilliwack Progress)
Vintage military aircraft moving from Chilliwack to new home at B.C. Aviation Museum

The challenging move to Vancouver Island will be documented by Discovery Channel film crews

Chartwell Malaspina Care Residence in Nanaimo. (News Bulletin file photo)
Another staff member tests positive for COVID-19 at Nanaimo care home

Chartwell Malaspina Care Residence employee is isolating, says Island Health

Actions of Vancouver Island RCMP emergency response team members prevented a potential head-on collision accident on the Trans-Canada Highway on Jan. 19, says Nanaimo RCMP. (News Bulletin file)
Eight cars evade vehicle driving on wrong side of highway, says Nanaimo RCMP

Incident occurred near Trans-Canada Highway-Morden Road intersection earlier this week

A video posted to social media by Chilliwack resident Rob Iezzi shows a teenager getting kicked in the face after being approached by three suspects on Friday, Jan. 22, 2021. (YouTube/Rob i)
VIDEO: Security cameras capture ‘just one more assault’ near B.C. high school

Third high-school related assault captured by Chilliwack resident’s cameras since beginning of 2021

FILE - In this Feb. 14, 2017, file photo, Oklahoma State Rep. Justin Humphrey prepares to speak at the State Capitol in Oklahoma City. A mythical, ape-like creature that has captured the imagination of adventurers for decades has now become the target of Rep. Justin Humphrey. Humphrey, a Republican House member has introduced a bill that would create a Bigfoot hunting season, He says issuing a state hunting license and tag could help boost tourism. (Steve Gooch/The Oklahoman via AP, File)
Oklahoma lawmaker proposes ‘Bigfoot’ hunting season

A Republican House member has introduced a bill that would create a Bigfoot hunting season

Economic Development and Official Languages Minister Melanie Joly responds to a question in the House of Commons Monday November 23, 2020 in Ottawa. THE CANADIAN PRESS/Adrian Wyld
Federal minister touts need for new B.C. economic development agency

Last December’s federal economic update promised a stimulus package of about $100 billion this year

Most Read