HomeSecurityNova Scotia Power: Data breach affects over 900,000 customers

Nova Scotia Power: Data breach affects over 900,000 customers

Nova Scotia Power has been forced to commit to stronger cybersecurity and privacy safeguards after a cyberattack exposed sensitive data of more than 900,000 current and former customers . The scope of the breach and the nature of the data exposed have raised serious questions about how organizations manage and protect customer data

Nova Scotia Power

The breach, discovered on April 25, 2025, was not the result of a single vulnerability. Instead, it unfolded over weeks, highlighting how attackers can move silently through systems before being detected.

Nova Scotia Power: Data Breach via Malware

According to details shared in a compliance letter, the Nova Scotia Power data breach began around March 19, 2025. An employee visited a compromised website , which was infected with the “ SocGholish ” malware , and clicked on a malicious pop-up link . This allowed the malware to be installed and access the network.

See also: GitHub Phishing: Fake OpenClaw tokens to steal crypto wallets

From there, the attackers escalated their access. Between April 8 and 22, they moved into the systems using domain administrator privileges, conducted internal reconnaissance, and collected credentials. This phase is critical and often underestimated in cybersecurity incidents.

By the time the Nova Scotia Power data breach was detected, the attackers had already spent days exploring the network.

Data Exfiltration and Ransomware Development

The final stage of the Nova Scotia Power data breach occurred between April 23 and 25, when the attacker extracted data from on-premises systems and cloud storage. Shortly thereafter, ransomware, backups were destroyed , and many applications stopped working.

The attack was discovered only when employees reported system outages, an indication that the breach had already reached its most destructive phase.

The attackers later contacted the company, providing evidence that they had access to sensitive customer data. However, there is no evidence that the data was made public or sold.

Nova Scotia Power chose not to pay the ransom, following the instructions of law enforcement authorities.

See also: Device code phishing attack has targeted 340+ organizations

Nova Scotia Power: Data breach affects over 900,000 customers

Scope of the Data Breach

The Nova Scotia Power data breach affected approximately 375,000 current and 540,000 former customers. The exposed data includes:

  • Names
  • Phone numbers and email addresses
  • Postal addresses
  • Dates of birth
  • Account and billing history (including bank details)
  • Driver's license numbers ‘Social Insurance Numbers (SINs)

The handling of the data breach has drawn criticism. The Office of the Privacy Commissioner of Canada received multiple complaints, particularly about delayed notifications and the use of mailed letters, which slowed communication with affected individuals.

There have also been concerns expressed regarding the collection and storage of SINs, which were part of the exposed data set.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

While Nova Scotia Power informed the public on April 28 and notified regulators by May 1, direct notifications to customers began weeks later, with additional affected individuals identified months after the initial disclosure.

This staged communication reflects the complexity of breach investigations, but also underscores the importance of transparency.

See also: Intellexa Tal Dilian: Shots against the Greek government

Response and Security Commitments

Following the data breach, the company took steps to contain the incident. This included isolating affected systems, restoring compromised credentials , and working with external cybersecurity experts to investigate and remediate the breach.

Nova Scotia Power: Data breach affects over 900,000 customers

Customers were offered credit monitoring and identity protection services, initially for 24 months. Later extended to five years for all customers.

At the same time, Nova Scotia Power has committed to strengthening its security measures . The Office of the Privacy Commissioner will continue to monitor progress until all commitments are met.

Commissioner Philippe Dufresne said: “I welcome this commitment from Nova Scotia Power to ensure stronger protections for its customers’ personal information. This privacy breach highlights the significant risks of cyberattacks to individuals and companies. Strong, proactive data protection, including robust safeguards, must be a priority for all organizations in this evolving threat.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS