Nova Scotia Power Data Breach Began with Malware Download, Report Reveals
A newly released report from the Office of the Privacy Commissioner of Canada has detailed how a single compromised website visit led to a massive data breach at Nova Scotia Power.
According to the report, the incident began around March 19, 2025, when an employee visited a website infected with Socgholish fake updates malware. After clicking a malicious pop-up link, malware was downloaded and installed on the company’s systems.
That initial access ultimately resulted in ransomware deployment and the exposure of sensitive data belonging to hundreds of thousands of customers.
Timeline of the Attack
The report outlines a clear progression:
March 19, 2025
- Employee visits compromised website
- Malware installed via fake update prompt
April 8–22
- Threat actor moves laterally across systems
- Domain administrator accounts leveraged
- Additional malware deployed for reconnaissance and credential harvesting
April 23–25
- Data exfiltrated from on-premises and cloud systems
- Backups destroyed
- Ransomware deployed
The breach was discovered on April 25 after employees reported system outages.
Scope of Impact
Nova Scotia Power determined that approximately:
- 375,000 current customers
- 540,000 former customers
were affected.
Compromised data varied by individual but may have included:
- Names
- Phone numbers
- Email addresses
- Mailing addresses
- Dates of birth
- Customer account history
- Bank account numbers
- Driver’s licence numbers
- Social Insurance Numbers (SINs)
The exposure of Social Insurance Numbers significantly increases identity theft risk and regulatory scrutiny.
How the Attack Escalated
This breach highlights a classic attack chain:
- Initial access via phishing-style malware
- Privilege escalation using domain admin credentials
- Credential harvesting
- Data exfiltration
- Backup destruction
- Ransomware deployment
The destruction of backups demonstrates that the attackers had extensive control over internal systems before ransomware was triggered.
This is not a “smash-and-grab” attack. It reflects prolonged network access and insufficient containment.
Organizations seeking to reduce dwell time and lateral movement risk often implement structured monitoring and escalation frameworks through professional Managed Security Services in Alberta & BC to detect credential abuse and anomalous admin activity earlier in the attack lifecycle.
Dark Web Exposure and Ransom Refusal
Nova Scotia Power confirmed it received communications from the threat actor, including a Tor link allegedly showing proof of stolen customer data.
The company did not pay a ransom.
As of reporting, there was no confirmed evidence that the stolen data had been publicly released or sold.
Regulatory Fallout and Corrective Measures
The Privacy Commissioner required Nova Scotia Power to:
- Delete all stored Social Insurance Numbers unless legally required
- Conduct an independent third-party information security assessment
- Submit findings to the Office of the Privacy Commissioner by October 31, 2026
The company also announced it would no longer require SINs for identity verification except where legally mandated.
Strategic Takeaway
This incident underscores several recurring realities in modern ransomware events:
- Initial access often begins with a single user action
- Domain-level privilege escalation accelerates impact
- Backup protection is critical
- Data exfiltration often precedes encryption
- Sensitive identity data dramatically increases long-term risk
Utilities and critical infrastructure organizations operate in high-risk environments due to their operational importance and large customer datasets.
Reducing exposure requires more than endpoint protection — it requires centralized visibility, privileged access monitoring, and proactive patch and credential management frameworks.
Organizations looking to strengthen broader IT governance and administrative oversight alongside security controls should evaluate their overall Managed IT Services in Alberta & BC strategy to ensure operational resilience.



