Calgary TELUS Convention Centre Listed by 8base Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Calgary TELUS Convention Centre Listed by 8base Ransomware Group (reported December 6, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
People who have dealt with the Calgary TELUS Convention Centre — as event clients, suppliers, staff, or visitors — may now face uncertainty about whether internal records that include their details were taken in a ransomware incident. Public reporting indicates the organisation was listed by the 8base ransomware group in early December 2023, with claims that internal files were exfiltrated. The number of people affected remains unknown, and many specifics have not been confirmed publicly.
For anyone whose name, contact information, or business dealings appear in those systems, the practical stakes are straightforward: stolen internal files can be used for phishing, impersonation, or further fraud long after the initial attack. This article sets out only what has been reported, what remains undisclosed, and what steps affected individuals can reasonably take.
What happened
On or around 6 December 2023 it was reported that the Calgary TELUS Convention Centre had been listed by the 8base ransomware group. According to the available summary, the group claimed that internal files were exfiltrated in a ransomware attack. No public figure has been given for the volume of data, the number of individuals whose information may be involved, or the precise date the intrusion occurred. The method of initial access has not been disclosed in the material provided.
The listing itself is a claim published by the threat actor on its leak site. Independent confirmation of the full scope, the exact contents of the files, or whether negotiations took place has not been supplied in the reported facts. At the time of the report the centre was also noted as operating as a temporary COVID-19 vaccination site, though that operational detail does not itself confirm what data was taken.
Inside 8base
8base is a ransomware operation that became publicly visible in 2022 and 2023. Like many contemporary groups, it has typically followed a double-extortion model: encrypting systems while also copying data, then threatening to publish the stolen material if a ransom is not paid. The group maintains a leak site where it names victims and, in some cases, posts samples or larger archives of purportedly stolen files.
Public reporting on 8base has described relatively standardised ransomware tooling, affiliate-style recruitment common to the ransomware-as-a-service ecosystem, and a focus on mid-sized organisations across multiple sectors and countries. The group’s leak-site posts are claims intended to pressure victims; they are not independent verification. In this instance, the facts state only that Calgary TELUS Convention Centre was listed and that internal files were said to have been exfiltrated. No further statements attributed specifically to 8base about this victim — such as ransom demands, file counts, or deadlines — appear in the provided record.
Who is Calgary TELUS Convention Centre?
The Calgary TELUS Convention Centre is a major events venue in Calgary, Alberta, offering meeting and exhibition space along with in-house or partnered services for décor, audio-visual production, food and beverage, and related show support. Organisations of this type routinely hold records on corporate clients, individual event organisers, contractors, employees, and sometimes attendees or temporary staff. During the period referenced in the report it was also functioning as a temporary COVID-19 vaccination site, which can involve additional logistical and scheduling data.
A breach at a convention centre is consequential because the organisation sits at the intersection of business, hospitality, and public-facing operations. Client contracts, supplier agreements, staff records, and operational files can contain personal and commercial information that third parties could misuse. Even when the precise contents of a theft remain unconfirmed, the mere possibility that such material left the organisation’s control creates lasting risk for the people and companies named in those systems.
The information in question
The reported facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of data types — such as names, email addresses, financial details, health-related scheduling information, or contract documents — has been disclosed. The number of people affected is listed as unknown.
Convention centres and similar venues typically maintain databases and document stores that can include contact details for clients and suppliers, booking and billing records, employee information, and operational correspondence. Because the exact contents of the files claimed by 8base have not been independently detailed in the available material, it is not possible to state as fact which specific categories were taken. Readers should treat any assumption about particular data elements as unconfirmed until official notification or verified disclosure occurs.
Why it matters
When internal files leave an organisation through a ransomware incident, the people named in them can face targeted phishing, business-email compromise, or identity-related fraud. Attackers or later buyers of the data may craft convincing messages that reference real events, invoices, or contacts. For the organisation, the consequences can include operational disruption, contractual and regulatory obligations to notify affected parties, and erosion of trust among clients and partners.
Because the scale and exact data types remain undisclosed, individuals cannot yet know with certainty whether they are affected. That uncertainty itself is a cost: monitoring accounts, scrutinising unexpected messages, and remaining alert for misuse become necessary precautions rather than optional ones. The listing by 8base does not automatically prove every claim the group makes, yet the reported exfiltration of internal files is sufficient reason for caution.
If your data was in this claimed breach
If you have a past or current relationship with the Calgary TELUS Convention Centre and are concerned your information may have been involved, consider the following practical steps:
- Treat unexpected emails, calls, or messages that reference the centre, events, invoices, or vaccinations with heightened scepticism; verify through known official channels before clicking links or supplying information.
- Monitor financial and email accounts for unfamiliar activity and enable multi-factor authentication where available.
- If you receive a formal notification from the organisation, follow the specific guidance it provides regarding credit monitoring or other support.
- Change passwords on any accounts that may have shared credentials or recovery details tied to addresses used with the centre.
- Run a free exposure scan of your email address to check whether it has already appeared in known breach datasets elsewhere, which can help you prioritise further hardening of your accounts.
Public detail on this incident remains limited. Stay alert for any official statements from the Calgary TELUS Convention Centre and rely on verified sources rather than unverified claims circulating online.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
WEBBER RESTAURANT GROUP Listed by 8base Ransomware GroupTelepizza Listed by 8base Ransomware GroupPORTBLUE Listed by 8base Ransomware GroupTexas Hotel and Lodging Association Listed by 8base Ransomware GroupLatest breaches
Publicly posted by 8base — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.