Full Report
A data leak involving albertarepublicans.com was reported in April 2026. See incident details, impact on customers, and recommended security measures.
Analysis Summary
# Incident Report: Unauthorized Exposure of Voter Data by The Centurion Project
## Executive Summary
In April 2026, a searchable online database containing the names and addresses of approximately three million Albertans was published without authorization by a group known as "The Centurion Project." The data originated from the Republican Party of Alberta and was hosted online for several days before a court injunction forced its removal. The incident is classified as a high-severity privacy violation, exposing millions to potential harassment, doxing, and targeted scams.
## Incident Details
- **Discovery Date:** April 27, 2026
- **Incident Date:** Reported April 30, 2026 (Active for several days prior)
- **Affected Organization:** albertarepublicans[.]com (Republican Party of Alberta)
- **Sector:** Political Organization
- **Geography:** Alberta, Canada
## Timeline of Events
### Initial Access
- **Date/Time:** Late April 2026
- **Vector:** Secondary Data Sharing / Third-Party Transfer
- **Details:** The Centurion Project, a pro-separation group, obtained a voter list originally maintained by the Republican Party of Alberta. The specific method of acquisition (e.g., leak, theft, or unauthorized sharing) was not explicitly detailed, but the data originated from the party's internal records.
### Lateral Movement
- **Details:** Not applicable in the traditional network sense; the incident involved the movement of a dataset from a political entity to a third-party group (The Centurion Project).
### Data Exfiltration/Impact
- **Details:** The Centurion Project created and hosted a public-facing, searchable database containing the personal information of 3,000,000 residents.
### Detection & Response
- **Discovery:** The database was identified on April 27, 2026.
- **Response actions taken:** Investigations were launched by Elections Alberta and the Alberta RCMP. Legal counsel successfully obtained a court injunction on April 30, 2026, to take down the database.
## Attack Methodology
- **Initial Access:** Acquisition of sensitive voter datasets from a political organization.
- **Persistence:** Data was hosted on an independent web platform for several days.
- **Privilege Escalation:** N/A (Data misuse rather than system intrusion).
- **Defense Evasion:** N/A.
- **Credential Access:** N/A.
- **Discovery:** Targeted identification of sensitive demographic information for political advocacy.
- **Lateral Movement:** Data transfer between the Republican Party of Alberta and The Centurion Project.
- **Collection:** Gathering of names and physical addresses of approximately 3 million individuals.
- **Exfiltration:** Publication of internal voter lists to the public internet.
- **Impact:** Unauthorized disclosure of PII (Personally Identifiable Information) leading to high privacy risk.
## Impact Assessment
- **Financial:** Costs associated with legal fees for the court injunction and ongoing government investigations.
- **Data Breach:** Names and physical addresses of ~3,000,000 individuals.
- **Operational:** Disruption of political data management and involvement of law enforcement (RCMP).
- **Reputational:** Significant loss of public trust in how political entities handle sensitive voter data.
## Indicators of Compromise
- **Network indicators:** albertarepublicans[.]com (Source of data); searchable database hosted by The Centurion Project (specific URL not provided).
- **File indicators:** Searchable voter registration database.
- **Behavioral indicators:** Unauthorized publication of private datasets for political/social advocacy.
## Response Actions
- **Containment measures:** Court injunction served to force the immediate removal of the searchable database.
- **Eradication steps:** Removal of the publicly accessible voter list from the host server.
- **Recovery actions:** Ongoing monitoring for data scraping and public advisories issued to affected Albertans.
## Lessons Learned
- **Key takeaways:** Secondary sharing of sensitive data with third-party groups without strict oversight creates massive liability.
- **What could have been done better:** Implementation of stricter data egress controls and more robust auditing of who has access to the Republican Party's master voter lists.
## Recommendations
- **Encryption:** All sensitive voter datasets should be encrypted at rest and in transit.
- **Access Control:** Implement the principle of least privilege (PoLP) for any third-party access to political databases.
- **Attack Surface Management:** Deploy continuous monitoring tools to detect unauthorized public-facing databases or misconfigured cloud storage containing PII.
- **Voter Notification:** Provide clear guidance to affected individuals on how to monitor for physical mail scams and phishing attempts.