LifeLabs, which does blood work and other tests across Canada, said in a letter to customers that their names, contact information, health card numbers and lab test results were exposed in a cyber attack on its computers in early November.
Most of those affected are in Ontario or British Columbia.
The company also said it paid an undisclosed sum to the hackers to retrieve the data, and has retained cyber security experts to isolate and secure its affected computers, as well as determine the scope of the breach.
“We want to emphasize that at this time, our cyber security firms have advised that the risk to our customers in connection with this cyber attack is low,” the company said in a statement.
It added that its security consultants “have not seen any public disclosure of customer data as part of their investigations, including monitoring of the dark web and other online locations.”
Ontario and British Columbia privacy commissioners Brian Beamish and Michael McEvoy said they are conducting a joint investigation into the breach, calling the scale of the attack “extremely troubling.

More from AFP
- European Police Arrest 42 After Cracking Covert App
- Dutch, European Hospitals ‘Hit by Pro-Russian Hackers’
- Cyberattacks Target Websites of German Airports, Admin
- Meta Slapped With 5.5 Million Euro Fine for EU Data Breach
- International Arrests Over ‘Criminal’ Crypto Exchange
- France Regulator Raps Apple Over App Store Ads
- More Political Storms for TikTok After US Government Ban
- Meta Hit With 390 Million Euro Fine Over EU Data Breaches
Latest News
- Germany Appoints Central Bank IT Chief to Head Cybersecurity
- OpenSSL Ships Patch for High-Severity Flaws
- Software Supply Chain Security Firm Lineaje Raises $7 Million
- ICS Cybersecurity Firm Opscura Launches With $9.4 Million in Series A Funding
- Vulnerability Provided Access to Toyota Supplier Management Network
- Patch Released for Actively Exploited GoAnywhere MFT Zero-Day
- Linux Variant of Cl0p Ransomware Emerges
- VMware Says No Evidence of Zero-Day Exploitation in ESXiArgs Ransomware Attacks
