Security

Cyber-crime

Canada goosed as attackers shutter hospitals and China deepfakes its politicians

Eh? Canucks cracked by cyber crims


Cybercriminals have Canada in the crosshairs, with five Ontario hospitals and a fresh Spamoflague disinformation campaign targeting "dozens" of Canadian government officials, including the PM.

The cyberattack against five southern Ontario hospitals has shut down IT systems, forcing them to cancel patient appointments over "the next few days," according to service provider TransForm. The statement said it was investigating whether any patient data was accessed during the incident, but couldn't say for sure yet.

On Monday, the services org posted an alert saying that its member hospitals and Windsor-Essex Hospice were experiencing a systems outage, which included email. "If your patients have a pre-booked appointment, please be advised they might be delayed or postponed," the notice said

Later that same day, TransForm provided an update on the hospitals' technical issues, and said it "determined that our member hospitals are experiencing a cyberattack." The intrusion, was affecting patient care "in various ways," according to Transform and the five member hospitals, which all posted the same alert on their websites.

The company spokesperson did not respond to The Register's inquiries about the security snafu.

TransForm is a nonprofit founded by the five — Windsor Regional Hospital, Erie Shores HealthCare, Hôtel-Dieu Grace Healthcare, Bluewater Health, and the Chatham-Kent Health Alliance — to manage their IT, supply chain, and accounts payable services. TransForm transmits one million patient-related messages each day and manages 10,000 devices, according to its website.

Spamouflage trolls PMs

Meanwhile, also on Monday the Canadian government reported that a disinformation campaign dubbed Spamouflage, apparently connected to the People's Republic of China, has been spamming government officials' Facebook and X (formerly Twitter) accounts since early August.

Spamouflage, also known as Dragonbridge, is the PCR's troll farm that Meta has linked to 7,704 Facebook accounts, 954 Facebook pages, 15 groups on the social network and 15 Instagram accounts, as well as over 50 other platforms, including X of course.

While most of the crew's work is decidedly spammy (beauty advice, cooking tips, and bot comments on others' social media accounts), some of its efforts have garnered more attention. This includes fake news stories ahead of the 2022 US midterm elections and trolling rare-earth mining companies, which prompted a Pentagon response.

More recently, the trolls have moved into pretty convincing deepfake news videos.

According to Global Affairs Canada, the Spamouflage campaign against politicians of all political stripes started in early August and accelerated over September's Labour Day long-weekend. The government said "thousands of comments" in English and French on Canadian Members of Parliaments' (MPs) Facebook and X accounts.

This included "dozens" of politicians from both parties and across all regions: Prime Minister Justin Trudeau, the Conservative-party leader of the Official Opposition Pierre Poilievre, and several members of Cabinet.

"These spam comments claimed that a critic of the Chinese Communist Party (CCP) in Canada had accused the various MPs of criminal and ethical violations," the government statement said.

"The Spamouflage campaign also included the use of likely 'deepfake' videos, which are digitally modified by artificial intelligence, targeting the individual."

Government officials notified the social media platforms, which then removed much of the spam, we're told. Not that new accounts won't be created; this kind of garbage is becoming a global problem, not just one confined to the Great White North. ®

Send us news
11 Comments

Five Eyes nations warn Moscow's mates at the Star Blizzard gang have new phishing targets

The Russians are coming! Err, they've already infiltrated UK, US inboxes

Uncle Sam probes cyberattack on Pennsylvania water system by suspected Iranian crew

CISA calls for stronger IT defenses as Texas district also hit by ransomware crew

2.5M patients infected with data loss in Norton Healthcare ransomware outbreak

AlphV lays claims to the intrusion

Fancy Bear goes phishing in US, European high-value networks

GRU-linked crew going after our code warns Microsoft - Outlook not good

Hershey phishes! Crooks snarf chocolate lovers' creds

Stealing Kit Kat maker's data?! Give me a break

Scores of US credit unions offline after ransomware infects backend cloud outfit

Supply chain attacks: The gift that keeps on giving

Belgian man charged with smuggling sanctioned military tech to Russia and China

Indictments allege plot to shift FPGAs, accelerometers, and spycams

Rogue ex-Motorola techie admits cyberattack on former employer, passport fraud

Pro tip: Don't use your new work email to phish your old firm

'Serial cybercriminal and scammer' jailed for 8 years, told to pay back $1.2M

Crook did everything from SIM swaps to fake verified badge scams

Dump C++ and in Rust you should trust, Five Eyes agencies urge

Memory safety vulnerabilities need to be crushed with better code

Mirai malware infects routers and cameras for new botnet

Akamai sounds the alarm – won't name the manufacturers yet

MOVEit victim count latest: 2.6K+ orgs hit, 77M+ people's data stolen

Real-life impact of buggy software laid bare – plus: Avast tries to profit from being caught up in attacks