NOTICE TO THE PUBLIC OF CYBERSECURITY INCIDENT
October 2, 2026
Kingston Police (KP) are now closing off the cybersecurity incident suffered by the service in January of last year. The internal investigation of the incident is complete. We have upgraded our cybersecurity practices and have created a plan for upgrading and strengthening our IT infrastructure. KP has reported the incident to our partners and oversight bodies at the Information Privacy Commissioner of Ontario (IPC), the Ontario Solicitor General, the Ontario Inspector General of Policing, the Ontario Provincial Police (OPP) and the Royal Canadian Mounted Police (RCMP). We are thankful for all the understanding and support that these agencies, the public and our employees have shown through a challenging time. Our goal is to keep and develop public confidence in our commitment to the welfare and safety of all persons residing in Kingston.
KP and the Kingston Police Services Board (KPSB) have developed plans, with the assistance of experts, to meet the ambitious standards of accountability and safety expected by our community as reflected in our IT infrastructure. KPSB plans to invest $3.9 million over the next three years into cybersecurity and improvements to IT infrastructure. Further, there will be a 50% increase of full-time IT staff resulting in an increase from four to six persons to support and facilitate the implementation of an improved IT infrastructure. In today’s digital age, advanced IT and cybersecurity are essential for effective communication, decision-making and uninterrupted service to the residents of Kingston. It is important that we make the necessary investments to ensure optimal service and security.
What happened:
Experts have completed their work and analysis. We are now able to understand and make clear to the public what happened. In brief, a threat actor used compromised account credentials to access KP Systems through KP's VPN application on January 1, 2025. KP's investigations were not able to determine how the credential compromise occurred. The intrusion was identified by our Acting Director of IT on January 3, 2025. All systems were shut down within a brief time. By this time, the threat actor had successfully encrypted and extracted 160 GB of data from KP servers. KP engaged the services of experts in cybersecurity and assistance from the province and the OPP’s cybersecurity unit to assist in the investigation of the incident and the restoration of services. KP is grateful to the experts who collaborated on a complete investigation, restoration of systems and strategic planning for the cybersecurity environment at the service. KP is also grateful to the policing partners, local and national, and the city, for their valuable assistance in maintaining and restoring services.
Experts engaged with the threat actor who agreed to delete the data in their possession and to share proof of deletion with KP. Since that time, the OPP, and partners from police agencies around the world, have continued to monitor the dark web, and there has been no evidence of disclosure of any of the data extracted in the nine months that have followed the incident.
Based on the available evidence, KP believes the likelihood of misuse or disclosure of the extracted information is low. However, while there is no evidence that the information has been disclosed, copied, or misused, it cannot be definitively ruled out that copies of the information were retained by the threat actor or disclosed elsewhere. The assessment of risk described in this notice is based on the evidence presently available, including forensic analysis and ongoing monitoring activities, and remains subject to the inherent limitations of those investigative methods. Ongoing monitoring reduces risk and supports early detection of any disclosure, but it cannot eliminate all uncertainty.
KP remains confident that the likelihood of disclosure of this data, particularly given the passage of time, is very low, but our partners remain vigilant in monitoring the dark web for signs of disclosure.
KP would like to be transparent with the public about what was taken. The approximately 160 GB of data was composed of 345,000 documents. Analysts culled the documents for duplication and junk (like newsletters and bulk e-mails). This reduced the population of documents for analysis to approximately 100,000 documents which were to be analysed to determine what personal information they contained. The extracted dataset was significantly corrupted during the extraction process. As a result, investigators were unable to perform a complete record-by-record review of all extracted data. Experts conducted a representative sample analysis to identify the types of information that may have been affected. While a more comprehensive manual review was considered, it was determined to be highly impractical and prohibitively resource intensive given the condition and volume of the extracted data. Accordingly, the categories of information described below represent the best information currently available and should not be interpreted as a complete accounting of all information contained within the extracted dataset.
We describe below the categories of personal information affected:
- Criminal court information. This information was contained in court dockets dating between 2009 and 2024. Based on information available, we estimate that about 51,000 individuals were impacted in this part of the extraction. Personal information in this group would include name, date of birth, offence details, plea, findings and sentences or other disposition.
- Provincial offence ticketing information. Based on available information, we estimate that between 50,000 and 100,000 persons were affected by this data, which was collected between 2012 and 2024. Information taken included name, date of birth, offence details, plea, finding and sentence or other disposition.
- Bail hearing lists. These contained information about adult and young offenders between 2009 and 2022. Based on available information, we estimate that this data contained information relating to about 68,000 persons. The name, date of birth and remand details appeared in this information.
- Excel reports. These dated from 2000 to 2023, and affected about 22,000 people. These reports contained information about individuals interacting with police including adult and young offenders, victims, witnesses, complainants, missing persons, and KP employees and police officers. This information included names, dates of birth, and offence details for those charged, convicted, arrested or ticketed.
- Remaining data. This information dated from 1998-2020 and affected approximately 80,000 persons. This information affected a wide cross-section of persons interacting with police. There are 2,000 driver license numbers, fewer than 1,000 social insurance numbers (likely of employees) and fewer than 250 persons’ credit card, health card or passport numbers.
You may have been affected by this incident if, at any point during the periods described above, you:
- Appeared in criminal court between 2009 and 2024;
- Received a provincial offence notice between 2012 and 2024;
- Appeared on a bail hearing list;
- Interacted with KP as a victim, witness, complainant, missing person, arrested person, charged person, convicted person, or recipient of a ticket;
- Were a current, former, retired, civilian or sworn employee of KP; or
- Otherwise provided personal information to KP within the date ranges described above.
Although KP has assessed the likelihood of misuse of the affected information to be low, individuals may wish to take reasonable precautions to protect themselves. Depending on the type of information involved, individuals may consider:
- Monitoring financial accounts and credit card statements for unusual activity;
- Obtaining and reviewing their credit report;
- Contacting their financial institution if they have concerns regarding financial information that may have been affected;
- Contacting the relevant government agency if they believe a government-issued identifier (such as a driver's licence, health card, passport, or Social Insurance Number) may have been compromised; and
- Remaining vigilant against suspicious communications, including phishing emails, text messages, or phone calls requesting personal information.
KP continues to assess the impact of the incident on affected records and information systems. Where records could not be fully restored, the scope of any resulting permanent data loss remains under review. Should additional information become available regarding permanent loss of records, that information will be communicated publicly.
Any person with a question may contact: cyberinfo@kpf.ca.
If a member of the public wishes to make a complaint about the data breach, that complaint may be made to the Information and Privacy Commissioner of Ontario (IPC) through their website at https://www.ipc.on.ca/en/resources/forms/file-privacy-complaint-under-ontarios-provincial-and-municipal-privacy-laws or by regular mail at: 2 Bloor Street East, Suite 1400 Toronto, ON, M4W 1A8.