Nova Scotia Power faces scrutiny over cybersecurity training, customer data and response to 2025 breach

Ally Bowes
3 Min Read
Nova Scotia Power faces scrutiny over cybersecurity training, customer data and response to 2025 breach

Article content“That was an oversight,” Williams said. Article contentHackers accessed names, dates of birth, account, billing histories and SINsArticle contentThe utility’s system was breached around March 19, 2025, and was discovered by Nova Scotia Power on April 25. Article contentNSP emphasized that it wasn’t the main customer system that was compromised; the 2021 copy in the repository staging area was accessed.  Article content“That’s where the threat actor gained access,” Williams said. Article contentWilliams continued, saying that while the utility knows the amount of information hackers got access to, there’s no way to determine what information was taken about individual customers. Article content“We can tell what’s been touched within the system and we can tell how much has been removed from the system, but we don’t know precisely what came out of the system,” he said. Article contentThe information available varied, including names, dates of birth, account and billing histories, preauthorized payment information and social insurance numbers. Article contentArticle contentNSP could not say how many social insurance numbers were contained in the 2021 copy but agreed to determine if they could provide that information to the board. Article contentNearly 400,000 former and current customers affected by breachArticle contentNSP announced they were responding to a cybersecurity incident April 28, 2025, confirming May 1 that customer information was accessed. Article contentBeginning May 13, it mailed letters of notification to nearly 277,000 affected customers. On June 25, NSP posted a public notice that former customers had also been affected. Article contentOn Oct. 31, following further analysis, around 97,000 additional customers were sent notification letters. Article contentRoberts referred to a report by Tricia Ralph from INQ Law, a consultant retained by the board, that said the time between the May letters and June notices was unreasonable. Article contentThe utility disagreed, with Williams saying that given the size and complexity of the investigation, their timing was “appropriate and reasonable.” Article contentFollowing the attack, those affected were offered two years of identity protection and credit monitoring through TransUnion’s myTrueIdentity. This was expanded in June 2025 to five years for all customers past and present. Article contentLanteigne said that while unused activation codes expired Dec. 31, customers who missed the deadline can still contact the utility for a code. Article contentThe hearing is set to continue through Thursday, if required. Article content

Share This Article