Bill C-8 and the Coming Baseline for Canadian Critical Infrastructure
June 24, 2025ToolShell: The SharePoint Zero-Day Canadian Defenders Could Not Ignore
July 23, 2025Through the first half of 2025, a loose collective often tracked as Scattered Spider ran a highly effective campaign against retail, aviation, insurance, and hospitality organizations. Canadians felt this directly when WestJet disclosed a cyber incident in June 2025, part of a broader wave affecting the airline and travel sector. The technical sophistication here is not the story. The story is the phone call.
The Playbook
These actors excel at identity-centric intrusion. Rather than burning a zero-day, they call the IT help desk, impersonate an employee, and talk a support agent into resetting a password or enrolling a new multi-factor authentication device. From there they pivot into cloud consoles, single sign-on portals, and SaaS admin panels, often moving to data theft and extortion within hours.
Why It Works
- Help desks are optimized for speed, and pressure plus a plausible story defeats a checklist.
- Self-service MFA enrollment lets an attacker register their own device once they control the account.
- SMS and push-based MFA can be phished or fatigued, so the second factor is not always a real barrier.
What Defenders Should Change
The fix is process and identity hardening, not a new appliance. We advise requiring strong, out-of-band identity verification before any password or MFA reset, ideally something the caller cannot simply recite, such as a manager callback for high-risk roles. Move toward phishing-resistant, hardware-backed authentication like FIDO2 keys or passkeys for administrators. Restrict who can perform MFA resets, log every reset, and alert on new device enrollments.
Takeaway
Assume attackers will call your help desk and sound convincing. Harden the identity lifecycle, verify humans out-of-band before resetting credentials, and adopt phishing-resistant MFA for privileged accounts. Social engineering remains the cheapest, most reliable initial-access technique, and it targets your people, not your perimeter.
