Technology

Nova Scotia Power Investigates Data Deletion Failures Following Cyberattack

Nova Scotia Power has acknowledged a significant cybersecurity breach that occurred in March 2025, affecting many customers. The organization has claimed to enhance its cybersecurity measures since the incident, which involved the theft of customer data, including social insurance numbers. Currently, officials are unable to explain why some customer information that should have been automatically deleted remained in their systems prior to the hack.

about 3 hours ago 18 Canadian Sources Corroborated
Listen
Listen to this article synthesis
Audio narration of the published summary.
Developing Merged from 18 Canadian reporting desks.

In March 2025, Nova Scotia Power experienced a serious cyberattack that compromised the data of hundreds of thousands of its customers. Following the incident, the organization reported that it had removed all social insurance numbers from its systems to prevent potential misuse of the stolen data. Since then, Nova Scotia Power has claimed to have implemented significant improvements to its cybersecurity infrastructure.

However, during a recent regulatory hearing, executives from Nova Scotia Power revealed that they could not ascertain why a backup of nearly three decades' worth of customer information was not deleted as intended. At the hearing, company officials stated that they have mechanisms designed to ensure that data is routinely deleted within cycles of no more than 90 days. Despite these systems being in place, the failure to delete the data as planned has raised questions about how customer information was managed prior to the cyberattack.

As the utility faces scrutiny regarding its cybersecurity practices, the Nova Scotia Energy Board is examining the measures the company took to protect customer data before, during, and after the breach. There are ongoing discussions about the effectiveness of these enhancements and whether they are sufficient to safeguard against future incidents.

This situation follows a series of concerns by regulators and customers about the ramifications of the breach, which not only exposed sensitive information but also highlighted potential weaknesses in the company's data management protocols. Further investigations are expected to provide more clarity on the discrepancies in data handling and the adequacy of the response to the breach.

Analyzed Canadian Outlets (18)

5 headlines · wire copies grouped

NS Power says it’s made ‘significant enhancements’ to cybersecurity ahead of hearing
1 outlet
Nova Scotia Power can’t explain why hacked customer data was not deleted as planned
1 outlet
Nova Scotia Power doesn’t know why hacked customer data wasn’t previously deleted
1 outlet
Nova Scotia Power faces scrutiny over cybersecurity training, customer data and response to 2025 breach
1 outlet