Nova Scotia Power, the province’s primary electric utility, has confirmed it fell victim to a sophisticated ransomware attack impacting approximately 280,000 customers.
The breach, which began several weeks ago, involved unauthorized access to internal systems and the subsequent theft of sensitive data. While the company has restored operations with assistance from cybersecurity experts, it revealed that the threat actor published stolen information, prompting widespread customer notifications and credit monitoring provisions.
The cyber incident, identified as a ransomware attack, targeted Nova Scotia Power’s digital infrastructure, encrypting critical systems and exfiltrating customer data.
The utility engaged third-party cybersecurity firms to isolate affected networks, mitigate further damage, and conduct forensic analyses.
Investigations suggest the attackers employed advanced techniques to bypass existing safeguards, though specific details about the ransomware variant or entry vectors remain undisclosed.
Notably, Nova Scotia Power emphasized it did not comply with ransom demands, a decision it attributes to adherence to sanctions laws and coordination with law enforcement agencies.
This aligns with recent guidance from the Canadian Centre for Cyber Security, which discourages payments to threat actors due to risks of repeated targeting and legal complications.
The company’s refusal to negotiate underscores growing institutional resistance to cybercriminal leverage tactics, though it has not ruled out potential operational or reputational repercussions.
Data Breach and Customer Notifications
The threat actor publicly released portions of the stolen data, compelling Nova Scotia Power to initiate a large-scale notification campaign.
Impacted customers—roughly 60% of the utility’s client base—received physical mail detailing the breach’s scope and remediation steps.
The compromised information reportedly includes names, addresses, account numbers, and potentially payment histories, though the utility has not confirmed whether financial credentials or Social Insurance Numbers were accessed.
To address identity theft risks, Nova Scotia Power partnered with TransUnion to offer affected individuals a two-year subscription to the myTrueIdentity® credit monitoring service at no cost.
The package includes real-time credit alerts, dark web surveillance, and identity restoration support. Customers are urged to enroll promptly and monitor their financial accounts for suspicious activity.
Additionally, the utility warned against phishing attempts via email, text, or social media, particularly messages impersonating Nova Scotia Power to extract further personal data.
Security Measures and Ongoing Investigations
Post-incident, Nova Scotia Power implemented “additional security protections” across its networks, though specifics—such as enhanced encryption protocols or multi-factor authentication—were not detailed.
Cybersecurity experts reported the investigation are likely conducting penetration testing and vulnerability assessments to identify residual weaknesses.
The company also faces regulatory scrutiny under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), which mandates breach disclosures and mitigation efforts.
Law enforcement agencies, including the Royal Canadian Mounted Police (RCMP) and Canadian Cyber Incident Response Centre (CCIRC), are collaborating to trace the attack’s origins.
Early indicators suggest possible ties to transnational ransomware groups, which often exploit utilities due to their critical infrastructure status.
Meanwhile, customers are advised to verify communications through official channels, avoid unverified links or attachments, and report anomalies to the utility’s cybersecurity team.
Nova Scotia Power apologized for the breach, reiterating its commitment to data security.
However, the incident highlights systemic vulnerabilities in energy sector cybersecurity frameworks, echoing concerns raised by the 2021 Colonial Pipeline attack in the U.S. As investigations continue, analysts anticipate increased regulatory pressure on utilities to adopt standardized cyber defenses and incident response protocols.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.