In March 2025, Nova Scotia Power experienced a serious cyberattack that compromised the data of hundreds of thousands of its customers. Following the incident, the organization reported that it had removed all social insurance numbers from its systems to prevent potential misuse of the stolen data. Since then, Nova Scotia Power has claimed to have implemented significant improvements to its cybersecurity infrastructure.
However, during a recent regulatory hearing, executives from Nova Scotia Power revealed that they could not ascertain why a backup of nearly three decades' worth of customer information was not deleted as intended. At the hearing, company officials stated that they have mechanisms designed to ensure that data is routinely deleted within cycles of no more than 90 days. Despite these systems being in place, the failure to delete the data as planned has raised questions about how customer information was managed prior to the cyberattack.
As the utility faces scrutiny regarding its cybersecurity practices, the Nova Scotia Energy Board is examining the measures the company took to protect customer data before, during, and after the breach. There are ongoing discussions about the effectiveness of these enhancements and whether they are sufficient to safeguard against future incidents.
This situation follows a series of concerns by regulators and customers about the ramifications of the breach, which not only exposed sensitive information but also highlighted potential weaknesses in the company's data management protocols. Further investigations are expected to provide more clarity on the discrepancies in data handling and the adequacy of the response to the breach.
Analyzed Canadian Outlets (18)
5 headlines · wire copies grouped