DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

“Shoot the Messenger,” Friday edition: Homewood Health resorts to threats and a court order?

Posted on October 15, 2021July 22, 2025 by Dissent

In July of this year, CTV News in Canada and DataBreaches.net reported on a breach involving Homewood Health  in Canada. Both CTV  and this site had become aware of the breach when data allegedly from Homewood showed up on a leak site called Marketo. Marketo claimed to have almost 300 GB of Homewood’s data for sale.

As is Marketo’s business model, they apparently first tried to get Homewood to pay them to remove the data from public access.  When that failed, they started dumping small amounts of data as proof of claim and to increase pressure on Homewood to pay them.

And as is this site’s usual routine, DataBreaches.net reached out to the victim — in this case, Homewood Health — with questions about the incident. As more information and data became available to this site from Marketo’s site, those questions were expanded.

Homewood Health ignored all of this site’s inquiries. That is their right, of course, but by ignoring inquiries and opportunities, they deprived themselves of the opportunity to try to tell their side of the story or to provide a statement that would have made the use of any screencaps unnecessary.  Instead they stonewalled and left this site in the position of using redacted screencaps to prove that this breach involved personal and sensitive information. It’s a shame that Homewood Health just didn’t acknowledge that forthrightly when asked repeatedly.

More than one month later, DataBreaches.net received a legal threat letter from Homewood’s external counsel — the Miller Thomson law firm.

The letter, which appears to be an attempt to intimidate this blogger and this site into destroying data and and chilling speech, contains patently false and defamatory claims about this blogger. I will respond to just a few of their allegations:

Your unauthorized publication of the Confidential Information and related unlawful actions constitute several violations of law, including but not limited to:
(a) conspiracy;
(b) defamation;
(c) extortion;
(d) unlawful interference with economic relations; and
(e) intentional infliction of emotional distress.

On July 21, 22, 23, and August 8, this site sent  inquiries to Homewood seeking information and clarification about the breach.  The inquiries were polite and contained no threats of anything, so it is not clear how Miller Thomson can claim that this blogger or site has engaged in any “extortion.”  Nor is it clear how I allegedly “conspired” with anyone when I am a solo blogger. Does Miller Thomson consider getting information from a source “conspiring?”

Their other allegations are also refuted by the facts.  Perhaps the lawyers just threw a bunch of allegations at the wall and hoped that some would stick?

The letter then goes on to make demands that basically attempt to censor reporting and decimate press freedom. Regular readers of this site already know how this site responds to attempts to chill speech and a free press.

So Homewood Health had multiple opportunities to issue a statement or to speak to me about the incident if they wished to try to have input to the reporting. They stonewalled this site and then resorted to legal threats.  And they apparently convinced a court in Calgary to issue a court order.  With all due respect to the Calgary court, I will not be responding to the court.

Great thanks to some terrific lawyers at Covington and Burling and Osler, Hoskin & Harcourt. Neither firm nor any of their employees are responsible for the opinions expressed in this blog post, however. 

Category: Breach IncidentsBusiness SectorCommentaries and AnalysesNon-U.S.Of Note

Post navigation

← US govt reveals three more ransomware attacks on water treatment plants this year
UK: Schools email marketing company told us to go away when we told them of exposed database creds, say infoseccers →

2 thoughts on ““Shoot the Messenger,” Friday edition: Homewood Health resorts to threats and a court order?”

  1. JQ says:
    October 17, 2021 at 7:19 pm

    Any luck reporting them to the Alberta Privacy Commissioner?

    1. Dissent says:
      October 17, 2021 at 10:08 pm

      What would I be reporting them for?

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • BlackSuit ransomware site seized as part of Operation Checkmate
  • The day after XSS.is forum was seized, it struggles to come back online — but is it really them?
  • U.S. nuclear and health agencies hit in Microsoft SharePoint breach
  • Russia suspected of hacking Dutch prosecution service systems
  • Korea imposes 343 million won penalty on HAESUNG DS for data breach of 70,000 shareholders
  • Paying cyberattackers is wrong, right? Should Taos County’s incident be an exception? (1)
  • HHS OCR Settles HIPAA Ransomware Investigation with Syracuse ASC for $250k plus corrective action plan
  • IVF provider Genea notifies patients about the cyberattack earlier this year.
  • Key figure behind major Russian-speaking cybercrime forum targeted in Ukraine
  • Clorox Files $380M Suit Alleging Cognizant Gave Hackers Passwords in Catastrophic 2023 Cyberattack

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Indonesia asked to reassess data privacy terms in new U.S. trade deal
  • Meta Denies Tracking Menstrual Data in Flo Health Privacy Trial
  • Wikipedia seeks to shield contributors from UK law targeting online anonymity
  • British government reportedlu set to back down on secret iCloud backdoor after US pressure
  • Idaho agrees not to prosecute doctors for out-of-state abortion referrals
  • As companies race to add AI, terms of service changes are going to freak a lot of people out. Think twice before granting consent!
  • Uganda orders Google to register as a data-controller within 30 days after landmark privacy ruling

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.