Global Affairs Canada and the RCMP were targeted in two separate cyber incidents in early 2024. The Global Affairs Canada (GAC) breach exposed employees’ personal information after attackers accessed the department’s network and intercepted VPN traffic. A February event targeted RCMP networks and triggered a criminal investigation; the federal account says RCMP operations were not affected but does not say whether data was accessed or stolen. Officials have not established a connection between the incidents.
What happened at Global Affairs Canada?
In January 2024, a threat actor exploited devices used by GAC, entered its internal network, intercepted virtual private network (VPN) traffic and exfiltrated employees’ personal information, according to the Office of the Privacy Commissioner of Canada. The department’s international-relations mandate makes its information holdings attractive targets, the Commissioner noted.
The Office of the Auditor General later described the incident as a month-long cyberattack that compromised GAC’s network and resulted in the theft of personal information. The Treasury Board’s account says the January incident affected remote-access services within Canada, while GAC’s critical services remained available. These accounts describe different aspects of the event: service impact, duration, network access and information exposed.
What is publicly known about the RCMP incident?
Treasury Board records a separate cyber event targeting RCMP networks in February 2024. The RCMP launched a criminal investigation. The federal account says the event did not affect RCMP operations and posed no known threat to the safety and security of Canadians.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
The public account provides less technical detail than the GAC disclosures. It does not describe how the RCMP network was targeted or say whether information was accessed or exfiltrated. That uncertainty should not be mistaken for confirmation that no data was taken.
How the two incidents compare
| Incident | Date | Network or service | Disclosed impact | Response and known details |
|---|---|---|---|---|
| Global Affairs Canada | January 2024 | Internal network and remote-access services; the Privacy Commissioner says attackers intercepted VPN traffic. | Employees’ personal information was exfiltrated. Treasury Board said critical services were not affected. | The Auditor General described a month-long attack. The Privacy Commissioner detailed the access path and personal-information exposure. |
| RCMP | February 2024 | RCMP networks; the attack method is not stated in the public account. | No impact on RCMP operations and no known threat to Canadians’ safety and security. Whether data was accessed or exfiltrated is not stated. | The RCMP launched a criminal investigation. |
Treasury Board’s account dates and distinguishes the two incidents, but does not establish that they were coordinated or carried out by the same actor. The Office of the Auditor General’s 2025 report also says Communications Security Establishment Canada responded to 1,017 cybersecurity events during fiscal year 2023–24. That is an agency-wide total, not a count of attacks on GAC or the RCMP.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Do later reports of suspicious website activity mean government systems were hacked?
No. In a separate statement dated September 29, 2026, the Canadian Centre for Cyber Security said it was assessing reports of suspicious activity, including suspected AI-agent activity, aimed at publicly accessible websites such as Government of Canada sites. It said there was no indication government systems had been compromised at the time. The Centre also noted that public websites routinely receive automated and potentially malicious requests, which do not by themselves prove a successful breach. See the Cyber Centre statement.
Quick Recap
Best Value
Rank #4
Rank #3
What the public record does—and does not—establish
- Established for GAC: attackers accessed the department’s internal network, intercepted VPN traffic and stole employees’ personal information.
- Established for the RCMP: a February 2024 cyber event targeted its networks and prompted a criminal investigation; the federal account reported no operational impact or known threat to public safety.
- Not established: a shared perpetrator or coordination between the GAC and RCMP incidents, the RCMP attack method, or whether RCMP data was exfiltrated.
- Separate later activity: the September 2026 website-activity report did not indicate a successful compromise at the time of the Cyber Centre’s statement.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →

