Hackers have released some of the data accessed during an April 28 cyberattack on Canadian company London Drugs, according to the CBC. The breach caused the company to shut down its stores across Western Canada, and they remained closed until May 7. The incident is part of a series of hacking attempts and included an attack on B.C. government systems.
In a statement, the Richmond, B.C.-based retailer said that that the leaked files might include “some employee information,” and described the situation as “deeply distressing.”
The statement also explains the company was “unwilling and unable” to pay a ransom to hackers described as “a sophisticated group of global cybercriminals.”
This response came after Brett Callow, a B.C.-based threat analyst with the antivirus software company Emsisoft reported on social media that the hacking group LockBit had released on the dark web what it claimed was London Drugs’ data.
British authorities have described LockBit as “the world’s most harmful cybercrime group.”
On May 23, LockBit released over 300 gigabytes of data, a huge amount representing individual records consisting mainly of London Drugs employees. The company says that there is no indication that any patient or customer databases were compromised. Callow believes that if the data indeed belongs to London Drugs, its release indicates that LockBit has “given up” on receiving money for the attack and is now showing future victims the consequences of refusing to pay ransom.
To pay or not to pay
London Drugs has notified employees whose personal information may have been compromised and is offering them credit monitoring and identity theft protection services. The company is reviewing the potentially stolen files and will inform affected employees about the specific personal information that was compromised.
Callow cautioned London Drugs employees to be “very skeptical” of any communications they receive and to avoid clicking on links in unfamiliar texts or emails. While the leaked data could potentially be used for identity-theft fraud, those types of practises are not routine and the risk is relatively low.
In February, the National Crime Agency (NCA) of the United Kingdom led a consortium of law enforcement agencies to disrupt LockBit’s activities, infiltrating LockBit’s network and compromising its entire criminal enterprise. The agency accuses LockBit of providing a global network of hackers with tools for their attacks.
A May 7 NCA statement identified a Russian man named Dmitry Khoroshev as the “administrator and developer of the LockBit ransomware group.” Khoroshev now faces asset freezes and travel bans, and U.S. authorities are offering a reward of up to $10 million for information leading to his arrest and conviction.
Business cyber insurance keeps evolving
Business cyber insurance has significantly advanced over the last few years and shifted from a purely defensive approach to a more proactive, offensive strategy.
Proactive cyber protection focuses on detecting and stopping cyber threats before they occur. The objective is to prevent claims from happening in the first place.
Cyber insurance companies are now using technology that can detect if ransomware has been deployed within an organization but hasn’t yet been activated and identify if an organization has been targeted by a phishing attack but the username and password haven’t been used yet. And this can be done without the organization having to install any new technology.
Canadian Underwriter explains that proactive cyber protection companies such as CFC Underwriting are using enhanced algorithms to create an accurate profile of a business in real time. This means processing about 208,000 data points within 10 milliseconds for a typical business.
“In real time, we identify every piece of technology connected to the internet that interacts with the insured,” says Jason Hart, CFC’s head of proactive insurance said, noting that there are 50 million devices connected to the internet that the service could apply to any of the 500 million businesses worldwide.
Proactive cyber then considers situational awareness and trends to assess the likelihood of an attack.
“The proactive service continuously evaluates risks and threats across people, technology, and processes, assessing trends and patterns to predict the likelihood of an attack,” Hart explains. CFC has had several successes already, including detecting ransomware at a brain injury clinic’s command-and-control infrastructure before it was activated and a compromised manufacturing business, including the CEO’s login credentials. They were then able to inform the companies and guide them to remove the risks, preventing the attack.
Businesses are consistently being targeted, with Hart reporting that CFC itself had been targeted 4.5 million times since the beginning of 2024. This is a typical number for a modern business.
This proactive approach demonstrates how cyber protection has evolved to not only respond to but also anticipate and prevent cyber threats, providing businesses with robust defense mechanisms in real-time.
Business cyber insurance: Coverage for the modern world
Lane’s Insurance is a leading Alberta-based brokerage, providing complete business insurance solutions for owners of companies both large and small. Lane’s works with the province’s most trusted carriers to protect you from today’s advanced digital threats, and much more.
To learn more, or to obtain a quote, please contact us in:







