Canada’s National Capital Commission (NCC) disclosed that an unauthorized party accessed its website database on August 28. The potentially exposed information includes website users’ names, email addresses, mailing addresses, and telephone numbers; the NCC publicly reported the privacy breach on September 22.
The NCC said it had no evidence that the information had been misused at the time of disclosure. It advised potentially affected individuals to watch for suspicious emails, messages, or calls seeking personal information, and said it had taken steps to address the incident while reviewing its security measures.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
The NCC disclosed the privacy breach and said it had no evidence at that time that the potentially exposed information had been used maliciously. It advised affected individuals to be alert for suspicious communications and said it had taken steps to address the incident while reviewing its security measures.
An unauthorized party accessed the National Capital Commission's website database, potentially exposing website users' names, email addresses, mailing addresses, and telephone numbers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.