Breach Reference
Scan your email →
Data breach reference · April 2024

Were you affected by the London Drugs breach?

Disclosed
Apr 28, 2024
Records affected
3,000,000
Type
Ransomware
Sector
General SMB

Check if your email appears in this breach.

One-click check against public breach records. No account required.

Takes 60 seconds. We never store your email address.

What happened

The LockBit ransomware group claimed responsibility for the April 2024 attack on London Drugs. The company refused to pay the demanded ransom and stores were closed across British Columbia, Alberta, Saskatchewan, and Manitoba for approximately a week.<br><br>The attackers subsequently released files containing employee information, including some corporate head-office human-resources records. The BC and Alberta privacy commissioners opened investigations.

The LockBit ransomware group claimed responsibility for the April 2024 attack on London Drugs. The company refused to pay the demanded ransom and stores were closed across British Columbia, Alberta, Saskatchewan, and Manitoba for approximately a week.

The attackers subsequently released files containing employee information, including some corporate head-office human-resources records. The BC and Alberta privacy commissioners opened investigations.

Reported impact: US$25M ransom demanded, refused

Source: OIPC BC

What to do if you were affected

Common questions about the London Drugs breach

When did the London Drugs breach happen?
The breach was disclosed in April 2024. Public reporting was carried by OIPC BC. The incident is categorized as: Ransomware.
How many people were affected?
Approximately 3000000 records were reported affected. Whether your specific data was among them depends on your relationship with London Drugs during the exposure window.
How do I check if my email was in this breach?
Enter your email in the scan form above. LeakTrace runs a check against known breach records and returns the result in under a minute. No account required.
What should I do if my data was exposed?
• If you are or were a London Drugs employee, place a fraud alert on your credit file.
• Monitor your bank and credit accounts for unusual activity.
• Update passwords on any account that shared credentials with your London Drugs work email.
• Watch for phishing emails referencing HR benefits or payroll.
• Consider a credit freeze via Equifax and TransUnion.
Is my data still at risk years later?
Yes. Breach data from years past continues to circulate on active infostealer channels and credential-stuffing marketplaces. The passage of time does not neutralize the exposure. Ongoing monitoring catches new exposures as they land instead of only the ones already disclosed publicly.

Other general smb sector breaches