April 15 Update
The majority of computer systems and web applications that people in Banff use to interact with the Town are fully available, and more than 80% of all internal systems used by employees are operational.
The Town of Banff disconnected web-based systems after unauthorized access to its systems was detected March 19, 2022. Although most residents would not have noticed any interruption in services, the Town did not restore public access to some web-based applications, as a measure to secure its network and allow a careful investigation of the cybersecurity incident.
All emergency and essential infrastructure systems were uninterrupted. The Town’s online systems that are fully available include:
- All banff.ca information web pages
- Action Requests/Report a Problem service
- Emergency Alerts
- Roadworks Notifications
- Community Calendar of Events
- Town Council Agendas, live meeting video streaming, meeting agendas and decision minutes
- Requests to speak to Council
- All Town of Banff email
- Online meeting systems
- Business Licensing
- Job Opportunities
- Town Bid/Tender Opportunities
- Community Grant Applications
- FireSmart Assessment Requests and Applications
- Events, Banners and Commercial Filming Applications
- Banff Viewpoints public input projects
- Zero Waste Trail web modules
- The Aster housing sales portal
- Commercial Waste Request Services
- Facility Rentals
- Recreation Programs and Classes Bookings
- Visitor Pay Parking systems
- Construction Project updates
- Town social media accounts
Several systems remain offline as part of the ongoing investigation, including:
- Unwanted Item Pickup (call 403.762.1240 to book the free garage removal service)
- Development Permit Viewer (a temporary web page is available)
- Resident Parking Permits (register at Town Hall or call 403.762.1294 or email email@example.com)
- Traffic Dashboard and Web Cameras
The Town’s Corporate Services Department and the independent cybersecurity team continue to investigate the impact of the cybersecurity incident. The Town was never prevented from accessing any of its systems or data, and no evidence has been found of misuse of any data stored by the Town.
The Town collects information of community members as part of program administration. The investigating team believes that this personal information is not at risk.
The Town collects personal information from its employees for the purpose of payroll, benefits and/or tax purposes, including social insurance numbers, banking information and birthdates. It is possible that some of this information was accessed by the third party. Although there is no evidence of misuse of any personal information, the Town has offered an option of credit monitoring to its employees as a precaution to help employees safeguard against financial harm or identity theft.
March 29 Update
Early last week, the Town of Banff contracted independent cybersecurity experts to assist the Town in assessing the impact of a cybersecurity incident detected on March 19, 2022, and to strengthen the security of the Town’s computer and network systems.
Although the cybersecurity investigation is ongoing, our advisors have confirmed that some personal information may have been accessed in the incident, but it remains too early to determine the extent to which personal information was accessed and the nature of the information. The Town does not have any evidence that any personal information has been misused.
“The protection and privacy of our residents and their personal information is the highest priority for the Town of Banff. It was very concerning to learn that any personal files may have been accessed,” said Jason Darrah, Director of Communications. “We take this very seriously and are working with our advisors to assess the impact to individuals’ personal information. We will provide updates to potentially affected individuals as appropriate.”
Further information about the cybersecurity incident:
- The Town’s security systems immediately identified the cybersecurity incident and took immediate steps to secure the systems and mitigate the impact to data and operations.
- The Town never lost access to its data or information systems.
- The Town’s critical systems were unaffected. Systems such as those for emergency response, water and wastewater systems remained fully operational.
“We recommend all employees and members of the public who may have exchanged information with the Town to follow best practices in protecting personal information, such as creating strong, unique passwords for all accounts and updating them regularly, and checking banking statements and credit information frequently,” said Darrah.
The Town of Banff is committed to data safety and is conducting a careful review of all systems data and all security protocols. The Town will provide updates where appropriate on this web page.
Any questions or media inquiries should be directed to Jason Darrah, Communications Director, Jason.firstname.lastname@example.org or 403-762-1207.
March 24 News Release
The Town of Banff was subject to a cybersecurity incident on March 19, 2022, which affected the Town’s computer systems.
Upon learning of the incident, the Town of Banff took steps to secure its systems and mitigate the impact to their data and operations. Independent cybersecurity experts have been retained to assist the Town in dealing with the matter in accordance with industry best practices.
“The protection and privacy of our residents and their personal information is of utmost importance to the Town of Banff. A team of cybersecurity experts are assisting the Town in assessing the impact while simultaneously strengthening the security of our systems,” said Jason Darrah, Director of Communications. “The Alberta Privacy Commissioner has been notified and we will work with officials on this incident.”
The Town of Banff is committed to data safety and is taking the matter very seriously and is asking its employees, the public and its partners for their patience as it seeks to remediate the situation.
The Town is committed to providing updates where appropriate and will provide updates on our website. Any questions or media inquiries should be directed to Jason Darrah, Communications Director, Jason.email@example.com or 403-762-1207.