22.08.2026

"Nova Scotia Power's Data Breach Sparks Outrage"

HALIFAX — Nova Scotia Power officials say they don’t know why a digital copy of almost three decades worth of customer information that was later stolen in a cyberattack was not automatically deleted as intended

In a recent hearing held in Halifax, officials from Nova Scotia Power addressed the circumstances surrounding a major cybersecurity incident that exposed the personal data of over 370,000 customers. The data, which was believed to have been accessed by Russia-based attackers in March 2025, included sensitive information such as addresses, phone numbers, banking information, and social insurance numbers (SINs).

Blake Williams, the vice-president of legal and regulatory affairs for Nova Scotia Power, explained that the company’s customer information system, launched in 1997, is outdated, likening its vulnerability to asking a child to operate an old VCR. However, he noted that a secondary software system, Microsoft Azure, had erroneously retained a backup of customer data, which was intended to be automatically deleted within a 90-day cycle. Unfortunately, this automated deletion process was not applied to the Azure copy, allowing the sensitive data to remain accessible long after its intended purge.

Williams acknowledged that the reason for this oversight remained unclear, stating that the automated system requires manual setup and the company could not deduce exactly how the data mishap occurred due to the time that has passed since. The cyberattack in March 2025 not only resulted in the theft of this crucial data but also severely disrupted Nova Scotia Power’s automatic billing system, leading to inflated bills for customers.

Amid criticism from politicians regarding the company’s handling of customer communications, Williams revealed that the utility began ceasing the collection of social insurance numbers in 2018. However, related to the security breach, existing SINs had not been purged from the system until a commitment was made in 2024 to delete all instances. As a result, the outdated copy from 2021 containing old customer data, including deleted SINs, remained vulnerable to hackers.

David Roberts, a legal advocate who participated in the hearings, commented that a simple error in the management of data systems could have prevented the breach entirely. He emphasized the need for a cultural shift within Nova Scotia Power and the importance of implementing a new customer information system designed to enhance security and mitigate future risks.

The interim leader of the Liberal Party, Iain Rankin, has renewed calls for an independent review of Nova Scotia Power, asserting that Nova Scotians are unfairly bearing the financial burden of the utility's operational failures. He highlighted the discrepancies in management of customer data and how this lapse has affected the financial responsibilities of ratepayers.

Additionally, NDP energy critic Susan Leblanc criticized the provincial government for not adequately safeguarding the privacy of Nova Scotians. She called for legislative action to ensure that companies must protect sensitive information, advocating for a governmental obligation to support citizens impacted by data breaches.

The Energy Department, prompted by Premier Tim Houston, stated its intent to assess Nova Scotia Power’s responses through public hearings but withheld further comment until the hearings concluded. The department criticized the utility for its lack of readiness, privacy concerns, and poor communication with customers, particularly during the issues of inaccurate bill estimations that followed the cyberattack.

This incident has highlighted significant vulnerabilities in the infrastructure of Nova Scotia Power and has spurred a call for improvement and accountability in how sensitive customer information is handled.