Computer worm wreaked havoc at federal health agency
Last Updated: Monday, March 31, 2008 | 12:12 PM ET
The Canadian Press
Related
The federal agency that helps protect Canadians against epidemics came down with a devastating case of computer cramps last year that could have put lives at risk.
Hundreds of computers at the Public Health Agency of Canada fell victim to a "worm," a bit of malicious software that nearly brought operations to a halt.
The infection began with just a few computers but spread like a Prairie grass fire, eventually knocking out 1,308 work stations in three cities and taking more than a month to eradicate, say newly released documents.
The "worm" also spread to Health Canada when infected agency computers tapped into the bigger department's data network, disabling 543 additional work stations in five of Health Canada's Ottawa-area offices.
The attack is estimated to have cost the agency up to $1.5 million, including down time for employees made idle by their ailing work stations. More than 50 technicians and other experts struggled for weeks to contain the damage.
A Nov. 26, 2007, post-mortem report on the emergency warned that "the total cost of this incident could have been higher if this event occurred during a time of public health crisis, including loss of life."
The Canadian Press reviewed a 600-page file on the attack obtained through the Access to Information Act.
Error messages began chain of events
The trouble began mid-afternoon on Monday, Jan. 15, last year when a few computer users at the agency and at Health Canada reported getting error messages.
The next day, at least 50 users were unable to connect to the shared Health Canada network. By the following week, up to 80 per cent of work stations at the Public Health Agency of Canada were infected in Winnipeg, Guelph, Ont., and the Ottawa area.
"Any documentation residing on the network, desktop, computer or server could have been compromised; most of network was affected," says an "injury assessment" from Feb. 8.
Government protocols require that sensitive, confidential information about patients, doctors, drugs, and so forth be stored on a highly secure server. But the injury assessment noted that "there is a lack of technical and administrative controls to control and audit the unauthorized storage of information on corporate desktops."
The released file suggests officials could not determine for certain whether confidential information leaked out.
And spokespersons for the public health agency and for Health Canada did not immediately respond to requests for comment and clarification, such as what kinds of sensitive information was placed at risk by the worm infestation.
The post-mortem report said officials were not able to identify the precise origin of the attack, but noted that it spread rapidly by exploiting known vulnerabilities in Microsoft Windows and in Symantec Client Security and Antivirus software.
Fixes, or patches, had been available to repair the vulnerabilities well before the worm attack "but were not rolled out to desktops prior to the outbreak."
The agency eventually brought in outside help, the consulting firm Third Brigade, which fought the persistent worm for 26 days. "In some cases, the machines were re-infected within 30 seconds of being cleaned," the company said in a report.
Unlike software viruses, which attach themselves to programs and files, worms are designed by hackers as stand-alone entities to interfere with computer operations.
They propagate through e-mail or weak security points in common software and, once in place, can be used by the attacker to remotely access sensitive, confidential information.
The worm that attacked the agency (W32/IRCBot-TO) was first identified in January 2007, joining thousands of other worms that have been launched into cyberspace over the last few years.
Share Tools
Top News Headlines
- Montreal protesters march in peaceful defiance
- The clanging of pots and pans sounded throughout Montreal's downtown core Saturday night and into early Sunday morning, as thousands of protesters marched on in peaceful — but loud — defiance of Bill 78. more »
- Quebec tornadoes cause millions in damage
- Environment Canada confirms that two tornadoes — one of which was classed as a moderate F-1 packing winds of up to 150 km/h — touched down near Montreal Friday night, causing millions of dollars in damage. more »
- Teen struck by lightning in Ottawa dies
- The victim of a Friday lightning strike during a storm in east Ottawa has died, CBC News has learned. more »
- Missing Winnipeg children found in Mexico
- Two Winnipeg children reported missing and possibly in Mexico have been found alive, according to unofficial reports from an agency that works to find missing people. more »
Latest Health News Headlines
- Alcohol addiction team wants higher energy drink prices
- Mixing alcohol with caffeine-rich energy beverages is a trend that is continuing to rise in Canada, despite repeated warnings that the combination is unsafe, a new report warns. more »
- How curry spice helps the immune system kill bacteria
- A spice used in curry dishes helps to prevent infection and now scientists think they've got a lead on how. more »
- Yellowknife toddlers catching hand, foot and mouth virus
- An outbreak of hand, foot and mouth disease in Yellowknife is causing many toddlers and their parents some major discomfort. more »
- Super microscope installed at University of Victoria
- What's heralded as the world's biggest microscope has arrived at the Unversity of Victoria, marking the culmination of a 10-year effort by one of the school's professors. more »
FEATURED HEALTH
- Teen struck by lightning in Ottawa dies
- Missing Winnipeg children found in Mexico
- Quebec tornadoes cause millions in damage
- Woman's remains found in hockey bag on Cape Breton river
- Montreal protesters march in peaceful defiance
- Pope's butler arrested in Vatican leaks scandal
- Everest team unable to bring down Toronto woman's body
- WWE apologizes to Brazil over Canadian's flag stomp
- What a Greek euro exit could mean for Canada

