USB drives missing with Canadian voter data

In one of the biggest privacy breaches in Canadian history, the personal data of over 2 million voters in the province of Ontario held on two USB drives has disappeared.

The incident happened in April but was only publicly reported Tuesday by the provincial chief electoral officer. Greg Essensa said the data on the drives wasn't encrypted, but was in a format that could only be accessed by proprietary provincial software or by a highly skilled programmer using commercial software.

"I'm deeply disturbed," said Ontario privacy commissioner Ann Cavoukian.

It's "the largest data breach that has occurred in the province," from either a public agency or a private sector business. The risk, she added, is someone could access personal information and steal peoples' identities.

It's not merely a black eye for the province. It's also an embarrassment because Cavoukain is known around the world as a privacy advocate.

"One of the reasons I was so disturbed is the data on millions of people was not encrypted," she added.

Elections Ontario isn't exactly clear what's on the drives, or whether the drives were stolen or are merely missing.

Essena told reporters the two drives have names, addresses, gender, birth dates and "any other personal information updates provided to Elections Ontario" by roughly half of people on the voters list last fall, and possibly, whether they voted. What's not on the drives are social insurance numbers, health card numbers, drivers licence information, credit card or banking information.

But after several months of investigating it still isn't sure what names were on the drives. It believes they covered 20 to 25 of the 49 electoral districts being worked on by staff at the time.

Even forensic experts hired by the department can't figure out which ridings were on the drives.

The department has done a "rigorous" search for the drive, Essensa said, and a full investigation by a private law firm and a forensics security firm, an investigation still ongoing. It's also been reported to the Ontario Provincial Police.

Meanwhile, he's advising all Ontarians to watch for "potential unusual activity" regarding any transactions with the province, banks, utilities and retailers.

An obviously frustrated Cavoukian said she has issued several orders to provincial civil servants that if data is to be transferred from a provincial computer to a portable device either it has to be de-personalized or encrypted.

However, for some reason neither happened in this instance at Elections Ontario.

A chastened Essensa told reporters that the department's policies "were not followed" and couldn't explain why.

However, he tried to suggest that the odds of the data being misused is low.

"If you were to put these keys into your computer now there's no [file] extension that comes on the files. You would not be able to identify exactly what software you would need to utilize them."

"There is no evidence that copies of personal information on two USB keys have been improperly accessed," he added, but out of "an abundance of caution" is telling the public now.

The USB drives had been to transfer data to laptops in a temporarily leased building where Elections Ontario was updating the voter registry. Laptops used by staff didn't have Internet access to the government's servers.

Staff were told to lock up the drives when they weren't in use.

Comments are now closed.
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Webroot SecureAnywhere Business

The lightest, fastest, easiest-to-manage, and most effective endpoint protection.

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.