Suncor Energy was breached on or around 21 June 2023 and disclosed the incident on 25 June. More than 1,500 Petro-Canada retail sites were unable to accept card payments, with cash the only reliable means of payment; some supplier payments were also affected, and the loyalty programme was unavailable through the app and website.
Petro-Canada customer rewards data was later confirmed breached. Field operations were reported unaffected. The company replaced desktop and laptop computers during recovery, and executives reported most normal operations restored some months later.
The Cost Landed On People With No Connection To It
A driver at a Petro-Canada forecourt has no relationship with Suncor’s IT estate, was not a party to any decision, and had no way to prepare. They arrived, found cards refused, and either had cash or did not.
We have argued at 24-1231 and 22-0224 that availability harm goes uncounted. This file adds the distributional point: the harm was spread thinly across a very large number of uninvolved people, and thin wide harm is the kind no regime has ever been built to measure.
Cash-Only Is Not Neutral
Falling back to cash sounds like a mild inconvenience and it is not evenly distributed. It excludes people who do not carry cash, which increasingly means most people, and it lands hardest on anyone whose journey was not optional.
We have recorded degraded-mode fallbacks at 22-1002, where a hospital system moved to paper, and 22-1104, where a government did. Each fallback works for some people and fails for others, and the failure is never recorded because nobody collects the names of the customers who left.
Replacing The Laptops
The reported replacement of desktop and laptop computers during recovery is the detail that indicates how the response was scoped: a decision that cleaning endpoints was less trustworthy than replacing them.
We filed that judgement at 23-0518, where a vendor told customers to replace appliances rather than patch them, and 22-0224, where wiped modems had to be physically swapped. It is the most expensive form of confidence and organisations reach for it when they cannot prove what an intruder touched.
Compiled from contemporaneous reporting and the company’s statements, listed below. No ransomware operation is named — none was authoritatively identified. No figure for affected loyalty accounts is asserted and no cost figure is carried. Graded high. Corrections: corrections@forensicpost.com.