Nova Scotia Power has confirmed a data breach, following a cyberattack discovered last month. The incident is linked to unauthorized access to critical parts of the company's IT infrastructure.

Nova Scotia Power, a subsidiary of energy giant Emera Inc., serves over 500,000 customers in Canada – residential, commercial and industrial – and manages nearly 95% of the local market. Its production activity exceeds 10,000 GWh annually, with an extensive distribution network reaching 32,000 kilometers.
See also: Coinbase: Revealed a customer data breach
On April 28, the company announced that it had detected suspicious activity on its internal network, without affecting the production and supply of electricity. However, the procedures for dealing with the incident had an impact on the operation of internal systems.
After further investigation, Nova Scotia Power announced on May 1 that there was a possibility of a customer data breach – something that was confirmed in a later update.
According to the announcement, the stolen information includes:
- Full name
- Telephone numbers
- Email addresses
- Residential and postal addresses
- Nova Scotia Power program participation details
- Date of birth
- Customer account history (energy consumption, support requests, payments, invoices and credit profile)
- Driving license number
- Social Security Number (SIN)
- Bank details (in some cases)
See also: Australia's AHRC victim of breach

Nova Scotia Power: The breach occurred earlier
In the new statement, Nova Scotia Power says the cyberattack actually occurred on March 19, 2025, much earlier than initially estimated. The new disclosure brings to light a significant time gap of nearly two months from the time of the breach to when notifications were sent to customers.
While the company says there is no indication that the exposed data has been used maliciously, it has taken precautions by offering those affected free two-year credit monitoring through TransUnion. It also urges customers to closely monitor their financial activity and be on the lookout for potential fraud attempts.
See also: Dior reveals customer data breach
At present, no ransomware group has claimed responsibility for the cyberattack.
This attack shows that even critical public infrastructure remains vulnerable to sophisticated digital threats. In a world where personal data is equivalent to digital money, such incidents are not just “IT issues” – they are issues of public safety and trust.
The data breach at Nova Scotia Power is particularly concerning for several reasons:
- Extent of exposed personal data
- Delay in updating
- Providing a free credit monitoring service is a step in the right direction, but it is more of a reaction than a prevention.
Companies must take protective measures to prevent attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
