Okay.
When the CRA says that it's a third party and when the company in question says that it's not aware of it, but if the company in question has an obligation to report these privacy breaches, then it would make sense to believe that it could be some other nefarious third party that had access to this information. Is that correct?