In 2014, the Heartbleed breach exposed the personal data of 900 Canadians. What followed was a race against time for RCMP Members who worked to solve the case.  

RCMP Sergeant (Sgt.) Eric Demers always had a thing for computers. 

Long before cybercrime became its own specialty, before dedicated units and specialized programs even existed, he was drawn towards technology and investigative work. When the opportunity came to join the Technological Crime Unit early in his career as a young Constable, he took it, completed a two-year study program, and became a computer Forensic Analyst. 

By April 2014, now a Sergeant, Demers had seen many cases – but nothing quite like Heartbleed. 

A Flaw Nobody Saw Coming 

Most Canadians have never heard of OpenSSL, but they rely on it every day. 

OpenSSL is a cryptographic library that secures internet communications. It is an invisible lock in your browser’s address bar when you log into your bank, file your taxes, or send an email. It underpins websites, government portals, and critical infrastructure around the world.  

In 2012, a code was added to OpenSSL as part of an extension called “Heartbeat”, designed to keep connections alive. Hidden inside that code was a flaw, subtle enough to go unnoticed for nearly two years, but dangerous enough to expose a significant portion of the internet when it finally came to light. 

When security researchers discovered it in April 2014, they named it Heartbleed. This vulnerability allowed anyone who could exploit the system to view server memory and silently extract data, including passwords, encryption keys, and personal information, without triggering a single alarm. No logs, no trace, and no warnings.  

Once the breach was publicly disclosed, hackers from Canada quickly got to work.  

The Clock Starts 

The call came quickly. The Canada Revenue Agency (CRA) confirmed what investigators feared: Heartbleed had been exploited on its servers. An attacker extracted approximately 900 Social Insurance Numbers (SINs) from CRA systems. People filing taxes, trusting a government portal with their most sensitive information had been exposed without knowing it. 

The CRA shut down its online portals, notified Canada’s Privacy Commissioner, and called in the RCMP to help.  

“Unlike many other types of intrusions, there are often no clear logs or indicators showing exactly what data was accessed,” Sgt. Demers explained. “There was an immediate risk of losing critical investigative leads if we didn’t act quickly.” 

Communication and coordination were critical in the hours after the breach was confirmed. 

The Invisible Crime Scene 

There is no yellow tape in a cybercrime investigation, no neighbourhood to canvas, and no physical evidence to collect. This crime scene existed only through data, with only the faintest of digital fingerprints left behind by someone who was trying very hard not to leave any.  

The subject used a virtual private network (VPN) to mask their identity and hide their true location from anyone watching.  

However, the VPN dropped and the connection faltered for long enough that the suspect’s real IP address was exposed. One slip, and the case was cracked open. 

“That single event gave us our first solid investigative lead,” Sgt. Demers said. 

Investigators obtained a warrant and requested subscriber information from an internet service provider. The results pointed to a specific residence, shared by a university computer science professor and his son, a computer science student. 

The Breakthrough 

With judicial authorization secured, RCMP Members, including the Technological Crime Unit in London, Ontario, executed a search warrant and seized all relevant electronic devices for forensic investigation.  

Every device was examined, though a specific portion of the data on the teen suspect’s laptop was encrypted, adding a layer of complexity. Members identified unencrypted portions of the system and located the password, unlocking the encrypted data and pressing forward. 

What they found left little room for doubt. 

On one specific device they found confidential personal information including Social Insurance Numbers, names, and addresses that matched what was stolen from the CRA. 

“There was no legitimate explanation for that information to be present on a personal computer,” said Sgt. Demers. “That device was linked directly to Stephen Solls-Reyes, solidifying him as the primary suspect.” 

Stephen Solls-Reyes was 19 years old and was a second-year computer science student at the University of Western Ontario. He was arrested on April 15, 2024, just four days after the breach was reported to the RCMP and charged with one count of unauthorized use of a computer and one count of mischief in relation to data.  

For Sgt. Demers, the moment of finding that data on the device was the one that stayed with him.  

“It transformed the case from a complex investigation into a solid, evidence-based file,” he added.  

Real People, Real Consequences 

Sgt. Demers pushes back on the idea that just because it happened digitally, this issue is somehow harmless.  

“Cybercrime can feel abstract, especially since much of the work happens behind screens. But the human impact is very real – and often long lasting.” 

900 Canadians had their SIN stolen. The impact extends well beyond the initial incident, as identity theft, damaged credit, and a lingering sense of violation can follow someone for years. 

The internet does not follow traditional borders, and neither do cybercriminals, nor cybercrime investigations. In this case, the attacker had also targeted Jersey Mail, a small email service provider in the United Kingdom. As a result of this breach, the company declared bankruptcy, and employees lost their jobs. 

“Once you begin to look beyond the technical aspects and speak with those affected, the scale of harm becomes very clear,” noted Sgt. Demers. “That’s what we focus on throughout the investigation – the real people and communities impacted by these actions.” 

Behind every log file and forensic image is a person whose life was disrupted. Keeping that human reality front and centre – even when the evidence is nothing but ones and zeros – is part of what makes a great RCMP Member, like Sgt. Demers and his colleagues who cracked this case.  

The Threat Doesn’t Stand Still 
 
The threats Canada faces today are more sophisticated than anything investigators encountered in 2014. In hindsight, Heartbleed represented a simpler era of technology. 

Today’s landscape looks very different, and the pressure on RCMP Members has grown with it. 

Those behind organized crime are now using artificial intelligence (AI) to automate attacks at a scale and speed that no single person could solve. While the Heartbleed case involved a single vulnerability, today’s technology can enable thousands of targets to be reached simultaneously. As threats evolve, organizations and individuals must continue strengthening their security practices and staying informed to better protect themselves. When those protections are breached, investigators must act quickly to identify those responsible, protect victims, and preserve critical evidence before it disappears. 

This is the part of policing most Canadians never see. While the news cycle moves on, RCMP Members are working through the night, coordinating with internet service providers, aligning intelligence with partner agencies, and racing to preserve evidence that could disappear at any moment. Their work is determined and careful on behalf of those who don’t yet know anyone is fighting for them. They build expertise, follow the evidence, and persevere through technically demanding investigations because real people are counting on them to get it right.