ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Canadian dealership AutoCanada says cyber attack compromised employees’ data

North American multi-location automobile dealership group AutoCanada said the sensitive personal information of its employees was compromised during a data security incident it suffered in August.

 

In a data security incident notice published on its website on August 11, the Edmonton, Alberta-based automobile dealership said it identified a data security incident that involved malicious actors infiltrating its internal network.

 

The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident. While the company did not share any further detail about the data security incident, on September 17, the Hunters International ransomware group claimed responsibility for the incident and listed AutoCanada as a victim on its data leak site.

 

The group claimed to be in possession of 3.9 TB of data stolen from the company, including its databases, NAS storages, executives’ data, financial documents, HR data, email communications, SQL database and more.

After the ransom payment deadline expired on September 20, the hacker group published the entire database on the dark web.

 

 

Following the data publication, AutoCanada, in a temporary FAQ page on its website said, “Our investigation is ongoing, and encrypted server content is being restored and analysed as part of our incident response.

 

“We are currently working to determine the full scope of the data impacted by the incident, which may include personal information collected in the context of your employment with AutoCanada,” the company explained. This FAQ page was, however, soon removed and replaced with the “Error 403 - This web app is stopped” message.

 

While the company said that data “may” have been exposed, a security researcher told BleepingComputer that the data leaked by the threat actor included employee data including their names, addresses, dates of birth, payroll information, social insurance numbers, copies of government-issued identification documents and more.

 

The company has started notifying affected individuals and has offered complimentary credit monitoring and identity protection services through Equifax to those affected by the incident.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543