Canada’s House of Commons Investigating Data Breach After Cyberattack
The breach exploited a critical Microsoft SharePoint flaw allowing unauthorized access to sensitive employee data, prompting heightened security alerts amid a sharp rise in cyberattacks, officials said.
- On Friday, August 9, 2025, the Canadian House of Commons experienced a cyberattack by an unidentified threat actor targeting its internal network.
- The threat actor exploited CVE-2025-53770 by leveraging advanced deserialization and ViewState abuse techniques, bypassing multi-factor authentication and single sign-on controls.
- Investigators found that compromised information included names, job titles, office locations, email addresses, and details of the House of Commons-managed computers and mobile devices.
- In response, the House of Commons warned employees and parliamentarians to be vigilant, while Canada’s Communications Security Establishment said it is supporting the investigation but cautioned attribution is difficult.
- Last Thursday, U.S. Cybersecurity and Infrastructure Security Agency issued an emergency directive on CVE-2025-53786, while Shadowserver reported over 29,000 unpatched Exchange servers in Canada.
13 Articles
13 Articles
Recent House of Commons Cyberattack Under Investigation
A recent cyberattack targeting the House of Commons is currently under investigation. “The House of Commons is working closely with its national security partners to further investigate this matter,” a spokesperson for the House of Commons told The Epoch Times in an Aug. 14 email. The spokesperson said the House of Commons cannot speak further about the incident at this time for “security reasons,” while investigations are still underway. Meanwh…
The House of Commons and a Canadian cybersecurity agency are investigating a major data theft that took place last Friday.
Canada's House of Commons hit by cyberattack, data possibly leaked online - could Microsoft SharePoint be to blame? - WorldNL Magazine
Canada’s House of Commons notified its employees of a cyberincidentIt lost sensitive employee data to unnamed hackersThreat actors apparently broke in through a Microsoft SharePoint flawCanada’s House of Commons has reportedly suffered a cyberattack which saw it lose sensitive employee data.A CBC report, citing an internal email that the organization sent to its staff, says the attack saw an unidentified threat actor exploit a “recent Microsoft …
Coverage Details
Bias Distribution
- 50% of the sources lean Left
Factuality
To view factuality data please Upgrade to Premium