Company Details
nrbhss
216
2,805
92
nrbhss.ca
0
NUN_1243276
In-progress


Nunavik Regional Board of Health and Social Services Company CyberSecurity Posture
nrbhss.caNunavik’s health and social services network includes the Nunavik Regional Board of Health and Social Services, the Inuulitsivik Health Centre (Hudson Bay) and the Ungava Tulattavik Health Centre (Ungava Bay). The signing of the James Bay and Northern Quebec Agreement (JBNQA) and supplementary agreements established guidelines for the development of health and social services in Nunavik. The organization of health care and social services is a provincial jurisdiction, but it is adapted to regional realities. Given the size of its population and its cultural characteristics, Nunavik is unique in combining curative and preventive methods. In the fields of health and social services, promotion, prevention and protection activities can be carried out in a more harmonious and natural fashion. The interveners and professionals of the Nunavik health and social service network face challenges at the health, cultural, social and financial levels. Human, physical and financial resources are constantly deployed to set up the infrastructures necessary to the well-being of Nunavimmiut. Nunavik Regional Board of Health and Social Services Created in 1995 by virtue of the Act respecting health services and social services, the Nunavik Regional Board of Health and Social Services’ (NRBHSS) principal mandate is to organize health and social service programs in the region (14 villages of Nunavik), evaluate those programs' effectiveness and ensure the users receive services of good quality appropriate to their needs. Further, it ensures the organization and efficient use of financial resources granted to the Nunavik region. The NRBHSS is an organization dedicated to improving the health and well-being of the populations of the 14 communities on its territory. Its overall mission is to adapt the health and social service programs to the population's needs and to the region's realities. Its head office is located in Kuujjuaq.
Company Details
nrbhss
216
2,805
92
nrbhss.ca
0
NUN_1243276
In-progress
Between 700 and 749

NRBHSS Global Score (TPRM)XXXX

Description: Cyberattack on Kuujjuaq Health Centre Exposes Clinical Records in 2025 Breach The Ungava Tulattavik Health Centre (UTHC) in Kuujjuaq disclosed a cyberattack in November 2025, revealing that sensitive clinical and administrative records may have been compromised. Initially believed to have caused no data exposure, further analysis confirmed that files containing patient and employee information were potentially accessed by malicious actors. UTHC detected the attack promptly, isolating the breach and securing its network. The health centre has since established a crisis unit, deployed enhanced surveillance tools, and notified financial institutions and local authorities. A joint investigation is underway with Québec’s Cyber Defence Operational Centre (CDOC), the Sûreté du Québec, and the Nunavik Regional Board of Health and Social Services (NRBHSS). Officials described the incident as a "major" attack, likely carried out by organized cybercriminal groups. UTHC has set up dedicated support channels for affected users and employees, including email and phone contacts for inquiries. While the full scope of the breach remains under review, the health centre has emphasized its commitment to transparency and data protection.


No incidents recorded for Nunavik Regional Board of Health and Social Services in 2026.
No incidents recorded for Nunavik Regional Board of Health and Social Services in 2026.
No incidents recorded for Nunavik Regional Board of Health and Social Services in 2026.
NRBHSS cyber incidents detection timeline including parent company and subsidiaries

Nunavik’s health and social services network includes the Nunavik Regional Board of Health and Social Services, the Inuulitsivik Health Centre (Hudson Bay) and the Ungava Tulattavik Health Centre (Ungava Bay). The signing of the James Bay and Northern Quebec Agreement (JBNQA) and supplementary agreements established guidelines for the development of health and social services in Nunavik. The organization of health care and social services is a provincial jurisdiction, but it is adapted to regional realities. Given the size of its population and its cultural characteristics, Nunavik is unique in combining curative and preventive methods. In the fields of health and social services, promotion, prevention and protection activities can be carried out in a more harmonious and natural fashion. The interveners and professionals of the Nunavik health and social service network face challenges at the health, cultural, social and financial levels. Human, physical and financial resources are constantly deployed to set up the infrastructures necessary to the well-being of Nunavimmiut. Nunavik Regional Board of Health and Social Services Created in 1995 by virtue of the Act respecting health services and social services, the Nunavik Regional Board of Health and Social Services’ (NRBHSS) principal mandate is to organize health and social service programs in the region (14 villages of Nunavik), evaluate those programs' effectiveness and ensure the users receive services of good quality appropriate to their needs. Further, it ensures the organization and efficient use of financial resources granted to the Nunavik region. The NRBHSS is an organization dedicated to improving the health and well-being of the populations of the 14 communities on its territory. Its overall mission is to adapt the health and social service programs to the population's needs and to the region's realities. Its head office is located in Kuujjuaq.

Year after year, the Commonwealth of Massachusetts has continued to pioneer bold legislative actions and programs, some of which have been embraced on a national scale. We are always looking for talented individuals to help us maintain this momentum and improve the services that millions of people d

Ontario Government | Gouvernement de l’Ontario The Ontario Government works to serve the public interest and uphold the public trust by providing Ministers with objective advice and expert guidance. The Ontario Public Service carries out the decisions and policies of the elected government with int

As the United States Postal Service continues its evolution as a forward-thinking, fast-acting company capable of providing quality products and services for its customers, it continues to remember and celebrate its roots as the first national network of communications that literally bound a nation

At the Home Office, we help to ensure that the country is safe and secure. We’ve been looking after UK citizens since 1782. We are responsible for: - working on the problems caused by illegal drug use - shaping the alcohol strategy, policy and licensing conditions - keeping the United Kingdom safe

Our mission is to promote student achievement and preparation for global competitiveness by fostering educational excellence and ensuring equal access. ED is dedicated to: • Establishing policies on federal financial aid for education, and distributing as well as monitoring those funds. • Collect

The Government of Canada works on behalf of Canadians, both at home and abroad. Visit www.Canada.ca to learn more. Canada’s professional, non-partisan public service is among the best in the world, and many of its departments and agencies place in Canada’s Top 100 Employers year after year. If you

The Department of Education is responsible for delivering the Victorian Government’s commitment to making Victoria the Education State, where all Victorians have the best learning and development experience, regardless of their background, postcode or circumstances. Education remains a cornerstone f

The Singapore Public Service works with the elected Government and Singaporeans to forge a common vision of Singapore’s future and bring it into reality. We take pride in living out our values of integrity, service and excellence. Follow us for stories on how our public officers are contributing

Nav er en viktig del av sikkerhetsnettet i velferdsstaten. Vi skal bidra til at flere kommer i arbeid og færre går på stønad, og samtidig sørge for at de som trenger det er sikra inntekt og økonomisk trygghet gjennom rett pengestøtte til rett tid. For å løse dette samfunnsoppdraget forvalter Nav om
.png)
Ungava Tulattavik Health Center was a victim of a cyberattack in November. An investigation into the incident is ongoing but files...
Mary Simon's tour of the Nunavik region of northern Quebec this week marks the first time she's been on an official visit to the area where...
The purpose of Bill 19 is to establish a legal framework specific to health and social services information, and the intention is to cover...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Nunavik Regional Board of Health and Social Services is https://nrbhss.ca/en/careers.
According to Rankiteo, Nunavik Regional Board of Health and Social Services’s AI-generated cybersecurity score is 736, reflecting their Moderate security posture.
According to Rankiteo, Nunavik Regional Board of Health and Social Services currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Nunavik Regional Board of Health and Social Services has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, Nunavik Regional Board of Health and Social Services is not certified under SOC 2 Type 1.
According to Rankiteo, Nunavik Regional Board of Health and Social Services does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Nunavik Regional Board of Health and Social Services is not listed as GDPR compliant.
According to Rankiteo, Nunavik Regional Board of Health and Social Services does not currently maintain PCI DSS compliance.
According to Rankiteo, Nunavik Regional Board of Health and Social Services is not compliant with HIPAA regulations.
According to Rankiteo,Nunavik Regional Board of Health and Social Services is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Nunavik Regional Board of Health and Social Services operates primarily in the Government Administration industry.
Nunavik Regional Board of Health and Social Services employs approximately 216 people worldwide.
Nunavik Regional Board of Health and Social Services presently has no subsidiaries across any sectors.
Nunavik Regional Board of Health and Social Services’s official LinkedIn profile has approximately 2,805 followers.
Nunavik Regional Board of Health and Social Services is classified under the NAICS code 92, which corresponds to Public Administration.
No, Nunavik Regional Board of Health and Social Services does not have a profile on Crunchbase.
Yes, Nunavik Regional Board of Health and Social Services maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/nrbhss.
As of January 25, 2026, Rankiteo reports that Nunavik Regional Board of Health and Social Services has experienced 1 cybersecurity incidents.
Nunavik Regional Board of Health and Social Services has an estimated 11,878 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.
Detection and Response: The company detects and responds to cybersecurity incidents through an incident response plan activated with yes, and third party assistance with santé québec’s cyber defence operational centre (cdoc), sûreté du québec, nunavik regional board of health and social services (nrbhss), and law enforcement notified with yes (sûreté du québec), and containment measures with blocked the attack, plugged the breach, secured the computer network, and remediation measures with implemented surveillance tools for security, created a crisis unit, and communication strategy with informed financial institutions, nunavik mayors, and the public; set up a dedicated information service for users and employees, and enhanced monitoring with yes (surveillance tools implemented)..
Title: Cyberattack on Ungava Tulattavik Health Centre (UTHC)
Description: Clinical records have potentially been exposed in a data breach of a Kuujjuaq health centre, which was the victim of a cyberattack orchestrated by malicious individuals in November 2025. Preliminary analyses indicated no sensitive data was compromised, but recent information reveals that files potentially containing clinical and administrative information concerning certain users and employees may have been leaked.
Date Detected: 2025-11-01
Date Publicly Disclosed: 2025-11-04
Type: Data Breach
Threat Actor: Organized and professional groups
Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Data Compromised: Clinical and administrative information concerning certain users and employees
Brand Reputation Impact: Serious event with compromise of sensitive data
Identity Theft Risk: High (users and employees urged to monitor bank activity and be alert to suspicious calls/emails)
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Clinical Information, Administrative Information and .

Entity Name: Ungava Tulattavik Health Centre (UTHC)
Entity Type: Healthcare Provider
Industry: Healthcare
Location: Kuujjuaq, Quebec, Canada
Customers Affected: Certain users and employees

Incident Response Plan Activated: Yes
Third Party Assistance: Santé Québec’s Cyber Defence Operational Centre (CDOC), Sûreté du Québec, Nunavik Regional Board of Health and Social Services (NRBHSS)
Law Enforcement Notified: Yes (Sûreté du Québec)
Containment Measures: Blocked the attack, plugged the breach, secured the computer network
Remediation Measures: Implemented surveillance tools for security, created a crisis unit
Communication Strategy: Informed financial institutions, Nunavik mayors, and the public; set up a dedicated information service for users and employees
Enhanced Monitoring: Yes (surveillance tools implemented)
Incident Response Plan: The company's incident response plan is described as Yes.
Third-Party Assistance: The company involves third-party assistance in incident response through Santé Québec’s Cyber Defence Operational Centre (CDOC), Sûreté du Québec, Nunavik Regional Board of Health and Social Services (NRBHSS).

Type of Data Compromised: Clinical information, Administrative information
Sensitivity of Data: High (potentially sensitive personal and health information)
Personally Identifiable Information: Yes (users and employees)
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Implemented surveillance tools for security, created a crisis unit.
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by blocked the attack, plugged the breach and secured the computer network.

Recommendations: Users and employees urged to regularly check bank activity, monitor online transactions, be alert to suspicious calls and emails, and never share passwords, SINs, or credit card numbers over the phone.
Implemented Recommendations: The company has implemented the following recommendations to improve cybersecurity: Users and employees urged to regularly check bank activity, monitor online transactions, be alert to suspicious calls and emails, and never share passwords, SINs and or credit card numbers over the phone..
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: UTHC StatementDate Accessed: 2025-11-04.

Investigation Status: Ongoing
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Informed financial institutions, Nunavik mayors and and the public; set up a dedicated information service for users and employees.

Stakeholder Advisories: Informed financial institutions and Nunavik mayors of the incident.
Customer Advisories: Dedicated information service available for users and employees (email and phone support). Urged vigilance regarding bank activity and suspicious communications.
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Informed financial institutions and Nunavik mayors of the incident. and Dedicated information service available for users and employees (email and phone support). Urged vigilance regarding bank activity and suspicious communications..
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Santé Québec’s Cyber Defence Operational Centre (CDOC), Sûreté du Québec, Nunavik Regional Board of Health and Social Services (NRBHSS), Yes (surveillance tools implemented).
Last Attacking Group: The attacking group in the last incident was an Organized and professional groups.
Most Recent Incident Detected: The most recent incident detected was on 2025-11-01.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2025-11-04.
Most Significant Data Compromised: The most significant data compromised in an incident was Clinical and administrative information concerning certain users and employees.
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was Santé Québec’s Cyber Defence Operational Centre (CDOC), Sûreté du Québec, Nunavik Regional Board of Health and Social Services (NRBHSS).
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident were Blocked the attack, plugged the breach and secured the computer network.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach was Clinical and administrative information concerning certain users and employees.
Most Significant Recommendation Implemented: The most significant recommendation implemented to improve cybersecurity was Users and employees urged to regularly check bank activity, monitor online transactions, be alert to suspicious calls and emails, and never share passwords, SINs and or credit card numbers over the phone..
Most Recent Source: The most recent source of information about an incident is UTHC Statement.
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.
Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was Informed financial institutions and Nunavik mayors of the incident., .
Most Recent Customer Advisory: The most recent customer advisory issued was an Dedicated information service available for users and employees (email and phone support). Urged vigilance regarding bank activity and suspicious communications.
.png)
Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement method by using the unsafe innerHTML property to render domain search results.
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.
A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.
An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint returns a list of cashier accounts, including names, email addresses, usernames, and passwords hashed using MD5. As MD5 is a broken cryptographic function, the hashes can be easily reversed using public tools, exposing user credentials in plaintext. This allows remote attackers to perform unauthorized logins and potentially gain access to sensitive POS operations or backend functions.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.