Security

CSO

London Drugs closes all of its pharmacies following 'cybersecurity incident'

Canadian stores shuttered 'until further notice'


Updated Canadian pharmacy chain London Drugs closed all of its stores over the weekend until further notice following a "cybersecurity incident."

On Sunday, the British Columbia-based giant with more than 80 outlets said an "operational issue" forced the closure of its locations across British Columbia, Alberta, Saskatchewan, and Manitoba.

"Pharmacists are standing by to support with urgent pharmacy needs," the biz said in a social media post. "We advise customers to phone their local store's pharmacy to make arrangements."

A London Drugs spokesperson told The Register a "cybersecurity incident," discovered on Sunday, was behind the store closures. They declined to answer specific questions about the break-in - including if ransomware was deployed - and issued the following statement:

Out of an abundance of caution, London Drugs stores across Western Canada remain temporarily closed until further notice following the discovery that it was the victim of a cybersecurity incident on April 28, 2024.

Upon discovering the incident, London Drugs immediately undertook countermeasures to protect its network and data, including retaining leading third-party cybersecurity experts to assist with containment, remediation and to conduct a forensic investigation. 

At this time, we have no reason to believe that customer or employee data has been impacted.

Pharmacists continue to stand by to support any customers with urgent pharmacy needs. We advise customers to phone their local store's pharmacy to make arrangements. 

We apologize for any inconvenience caused and we want to assure you that this incident is the utmost priority for us at London Drugs.

While there is no indication who or what caused incident, or if ransomware was involved, the disruption echoes the earlier Change Healthcare ransomware infection in the US that also impacted pharmacies' ability to fill prescriptions and check patients' eligibility for medications. 

And it comes as criminals increasingly target healthcare organizations and their suppliers with extortion and other cybercrimes. 

In October, five southern Ontario hospitals shut down their IT systems and canceled patient appointments following a cyberattack against the hospitals' service provider TransForm.

TransForm is a nonprofit founded by the Ontario hospitals: Windsor Regional Hospital, Erie Shores HealthCare, Hôtel-Dieu Grace Healthcare, Bluewater Health, and the Chatham-Kent Health Alliance. It manages their IT, supply chain, and accounts payable services, and transmits one million patient-related messages each day.

Ransomware crew Daixin Team took responsibility for the intrusion, and claimed to have stolen millions of patients' records that were later leaked online, after hospital officials refused to pay the gang's ransom demands. ®

Updated to add at 2330 UTC

Spokespeople for London Drugs have been in touch to say the phone lines are now down, and people should instead go to their stores for help. So, the opposite of what they said earlier. Here's their statement:

As a necessary part of its internal investigation, London Drugs phone lines have been temporary taken down and will be restored as soon as the investigation permits it.

In the interim, pharmacy staff are on-site at all London Drugs locations to support customers with urgent pharmacy needs. We advise customers to visit their local store in-person for immediate support and until the phone lines are back in service.

Does that mean the stores are actually open? No. We asked if the pharmacies were opened or closed, and were told:

Stores remain closed until further notice while pharmacy staff are on-site at all stores to support customers with urgent pharmacy needs. Phone lines are currently down.

Send us news
20 Comments

Alleged Karakut ransomware scumbag charged in US

Plus: Microsoft issues workaround for dual-boot crashes; ARRL cops to ransom payment, and more

Volt Typhoon suspected of exploiting Versa SD-WAN bug since June

The same Beijing-backed cyber spy crew the feds say burrowed into US critical infrastructure

Iran's Pioneer Kitten hits US networks via buggy Check Point, Palo Alto gear

The government-backed crew also enjoys ransomware as a side hustle

Uncle Sam charges Russian GRU cyber-spies behind 'WhisperGate intrusions'

Feds post $10M bounty for each of the six's whereabouts

Transport for London confirms cyberattack, assures us all is well

Government body claims there is no evidence of customer data being compromised

Planned Parenthood confirms cyber-attack as RansomHub threatens to leak data

93GB of info feared pilfered in Montana by heartless crooks

Cicada ransomware may be a BlackCat/ALPHV rebrand and upgrade

Researchers find many similarities, and nasty new customizations such as embedded compromised user credentials

White House seizes 32 domains, issues criminal charges in massive election-meddling crackdown

Russia has seemingly decided who it wants Putin the Oval Office

North Korean scammers plan wave of stealth attacks on crypto companies, FBI warns

Feds warn of 'highly tailored, difficult-to-detect social engineering campaigns'

Novel attack on Windows spotted in phishing campaign run from and targeting China

Resources hosted at Tencent Cloud involved in Cobalt Strike campaign

Iran hunts down double agents with fake recruiting sites, Mandiant reckons

Farsi-language posts target possibly-pro-Israel individuals

Feds claim sinister sysadmin locked up thousands of Windows workstations, demanded ransom

Sordid search history 'evidence' in case that could see him spend 35 years for extortion and wire fraud