Tuesday, 22 September 2026 The Plausible Post Independent news from around the world, around the clock.

Audit Finds $1.3bn Federal Cloud Deal Let Telecom Pull Unredacted Files from Millions of Accounts

A federal audit published on 21 September says a national digital‑locker contract gave commercial engineers live access to user files and routed millions in payments through opaque firms. The government has frozen data migrations and faces calls for a criminal probe as opposition MPs demand answers.

By Verda R. Breitenberg ·

AuroraTel headquarters, Toronto: auditors say company engineers used privileged access keys during the federal Locker rollout. Photo taken 21 September 2026.
AuroraTel headquarters, Toronto: auditors say company engineers used privileged access keys during the federal Locker rollout. Photo taken 21 September 2026.

A public audit released on Monday (21 September 2026) found that a $1.3 billion‑CAD (about €850m / $960m) contract between the federal government and telecom firm AuroraTel included clauses that allowed commercial staff to retrieve unredacted files from the new Pan‑Canadian Digital Locker service. The audit says those so‑called maintenance powers were not spelled out to Parliament and were accompanied by a network of subcontracts worth a further $175 million‑CAD (about €115m / $130m) that flowed to firms with opaque ownership structures.

The Auditor General’s report says approximately 5.6 million Canadians had accounts linked to the Locker at the time the contract was signed in late 2024, and that routine data migrations were already under way when the access entitlement was exercised. The government announced an immediate halt to migrations and said it had suspended parts of the contract pending an external review.

Server racks at one of the data centres where Pan‑Canadian Locker data was hosted. The audit flags maintenance access used on live systems.
Server racks at one of the data centres where Pan‑Canadian Locker data was hosted. The audit flags maintenance access used on live systems.

What the audit found

The 92‑page audit, obtained and published by the Auditor General’s office, describes a technical backdoor in the platform: AuroraTel engineers and a small team from subcontractor Northern Bay Holdings were issued long‑lived API tokens that bypassed the service’s redaction and consent screens. The report says the tokens were justified in procurement paperwork as a temporary “debugging” measure but were used in live environments.

The Auditor General’s report was filed with Parliament and released publicly on 21 September 2026.
The Auditor General’s report was filed with Parliament and released publicly on 21 September 2026.

“The tokens permitted access to whole files, including medical records and legal documents, without the same user consent recorded in the public interface,” the report states. Ex‑AuroraTel systems engineer Matúš Bača‑Virčíková, who spoke to reporters after providing testimony to the audit team, said the arrangement was known inside the company as a way to speed problem resolution. “I was given keys that pulled raw data. Management called it maintenance; customers saw it as private,” he said.

Map of the federal Locker’s hosting footprint; the audit highlights concentration of mirrored data in three provinces.
Map of the federal Locker’s hosting footprint; the audit highlights concentration of mirrored data in three provinces.

More news