Breach Reference
Scan your email →
Data breach reference · December 2019

Were you affected by the LifeLabs breach?

Disclosed
Dec 17, 2019
Records affected
15,000,000
Type
Ransomware / data theft
Sector
Healthcare / Medical Clinic

Check if your email appears in this breach.

One-click check against public breach records. No account required.

Takes 60 seconds. We never store your email address.

What happened

In November 2019, LifeLabs disclosed a cyberattack in which attackers accessed a system containing customer information including names, addresses, email addresses, login credentials, dates of birth, health card numbers, and lab test results.<br><br>A joint investigation by the Ontario and British Columbia privacy commissioners found LifeLabs had failed to take reasonable steps to protect the personal health information in its custody. Approximately 85,000 lab test results dated from 2016 or earlier were also exposed.

In November 2019, LifeLabs disclosed a cyberattack in which attackers accessed a system containing customer information including names, addresses, email addresses, login credentials, dates of birth, health card numbers, and lab test results.

A joint investigation by the Ontario and British Columbia privacy commissioners found LifeLabs had failed to take reasonable steps to protect the personal health information in its custody. Approximately 85,000 lab test results dated from 2016 or earlier were also exposed.

Reported impact: Undisclosed ransom paid, class-action settlements pending

Source: IPC Ontario

What to do if you were affected

Common questions about the LifeLabs breach

When did the LifeLabs breach happen?
The breach was disclosed in December 2019. Public reporting was carried by IPC Ontario. The incident is categorized as: Ransomware / data theft.
How many people were affected?
Approximately 15000000 records were reported affected. Whether your specific data was among them depends on your relationship with LifeLabs during the exposure window.
How do I check if my email was in this breach?
Enter your email in the scan form above. LeakTrace runs a check against known breach records and returns the result in under a minute. No account required.
What should I do if my data was exposed?
• Watch for phishing emails or phone calls referencing health services.
• Review any accounts secured by health card number.
• Enable two-factor authentication on your patient-portal accounts.
• Be cautious of unsolicited communications asking to verify medical information.
• Contact LifeLabs support if you receive suspicious communication referencing your lab results.
Is my data still at risk years later?
Yes. Breach data from years past continues to circulate on active infostealer channels and credential-stuffing marketplaces. The passage of time does not neutralize the exposure. Ongoing monitoring catches new exposures as they land instead of only the ones already disclosed publicly.