
The Canadian Nurses Association (CNA), representing a substantial number of healthcare professionals across Canada, has officially confirmed a significant data breach earlier this year.
The CNA acknowledged that on April 3, it fell victim to a security breach involving the theft of sensitive information.
Fortunately, this breach did not disrupt its operations but did impact certain systems. The association promptly responded by initiating an investigation and collaborating with third-party cybersecurity experts. In addition, as a precautionary measure, they reported the incident to law enforcement authorities.
A CNA spokesperson stated, "We have since completed our investigation into the incident, and any members affected by this breach are being informed accordingly." Furthermore, the association actively engages with its members and industry partners to bolster its security measures to prevent similar incidents.
The breach initially garnered attention when two distinct ransomware groups, Snatch and Nokoyawa, claimed responsibility for the attack in May. However, on September 1, the Snatch group, which had purportedly transitioned to focusing solely on data exfiltration and extortion without ransomware, leaked a staggering 37 gigabytes of data from the CNA.
Confusion surrounded the hacker group’s identity and operations, especially following the creation of a Telegram channel by a group with the same name in July. While they confirmed not using ransomware during the attack, they provided conflicting information about their connection to the ransomware group. Notably, both groups employed the same URL for their leak sites, adding to the ambiguity.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543