Yet another external Report that is damning of TTC practices. No doubt Rick Leary is not personally responsible but...
https://www.cp24.com/news/ttc-lacke...ernal-warning-years-earlier-reports-1.6947986
A report by the provincial privacy watchdog has found that Toronto’s public transit system was not prepared for the cyberattack that knocked down some of its communication systems and compromised the private information of more than 25,000 employees in 2021 -- despite an internal warning from the commission's security department issued years prior.
The breach, first reported in late 2021, compromised the personal information of approximately 25,000 past and present employees. That information included employee names, addresses, and social insurance numbers (SIN). The attack also took down several customer-facing systems, including trip-planning apps, the TTC website, and the online Wheel-Trans online booking portal.
While the TTC has released few details about the breach,
a report authored by Ontario’s Information and Privacy Commissioner (OIPC) that was released in April sheds some new light on what happened, including the fact that it was made possible after an employee fell for a phishing attempt.
The report also suggests that the breach was exacerbated by a failure of the commission to ensure its security software was kept up-to-date, despite having standards in place that instructed otherwise.