Nova Scotia Power Data Breach Began with Malware Download, Report Reveals

A newly released report from the Office of the Privacy Commissioner of Canada has detailed how a single compromised website visit led to a massive data breach at Nova Scotia Power.

According to the report, the incident began around March 19, 2025, when an employee visited a website infected with Socgholish fake updates malware. After clicking a malicious pop-up link, malware was downloaded and installed on the company’s systems.

That initial access ultimately resulted in ransomware deployment and the exposure of sensitive data belonging to hundreds of thousands of customers.


Timeline of the Attack

The report outlines a clear progression:

March 19, 2025

  • Employee visits compromised website
  • Malware installed via fake update prompt

April 8–22

  • Threat actor moves laterally across systems
  • Domain administrator accounts leveraged
  • Additional malware deployed for reconnaissance and credential harvesting

April 23–25

  • Data exfiltrated from on-premises and cloud systems
  • Backups destroyed
  • Ransomware deployed

The breach was discovered on April 25 after employees reported system outages.


Scope of Impact

Nova Scotia Power determined that approximately:

  • 375,000 current customers
  • 540,000 former customers

were affected.

Compromised data varied by individual but may have included:

  • Names
  • Phone numbers
  • Email addresses
  • Mailing addresses
  • Dates of birth
  • Customer account history
  • Bank account numbers
  • Driver’s licence numbers
  • Social Insurance Numbers (SINs)

The exposure of Social Insurance Numbers significantly increases identity theft risk and regulatory scrutiny.


How the Attack Escalated

This breach highlights a classic attack chain:

  1. Initial access via phishing-style malware
  2. Privilege escalation using domain admin credentials
  3. Credential harvesting
  4. Data exfiltration
  5. Backup destruction
  6. Ransomware deployment

The destruction of backups demonstrates that the attackers had extensive control over internal systems before ransomware was triggered.

This is not a “smash-and-grab” attack. It reflects prolonged network access and insufficient containment.

Organizations seeking to reduce dwell time and lateral movement risk often implement structured monitoring and escalation frameworks through professional Managed Security Services in Alberta & BC to detect credential abuse and anomalous admin activity earlier in the attack lifecycle.


Dark Web Exposure and Ransom Refusal

Nova Scotia Power confirmed it received communications from the threat actor, including a Tor link allegedly showing proof of stolen customer data.

The company did not pay a ransom.

As of reporting, there was no confirmed evidence that the stolen data had been publicly released or sold.


Regulatory Fallout and Corrective Measures

The Privacy Commissioner required Nova Scotia Power to:

  • Delete all stored Social Insurance Numbers unless legally required
  • Conduct an independent third-party information security assessment
  • Submit findings to the Office of the Privacy Commissioner by October 31, 2026

The company also announced it would no longer require SINs for identity verification except where legally mandated.


Strategic Takeaway

This incident underscores several recurring realities in modern ransomware events:

  • Initial access often begins with a single user action
  • Domain-level privilege escalation accelerates impact
  • Backup protection is critical
  • Data exfiltration often precedes encryption
  • Sensitive identity data dramatically increases long-term risk

Utilities and critical infrastructure organizations operate in high-risk environments due to their operational importance and large customer datasets.

Reducing exposure requires more than endpoint protection — it requires centralized visibility, privileged access monitoring, and proactive patch and credential management frameworks.

Organizations looking to strengthen broader IT governance and administrative oversight alongside security controls should evaluate their overall Managed IT Services in Alberta & BC strategy to ensure operational resilience.

about happier IT

We’re a Canadian-owned Managed IT Services provider supporting growing businesses across Alberta, British Columbia, and Ontario. From day-to-day tech support to long-term strategy, we help organizations stay productive, protected, and future-ready.

GET YOUR
FREE CONSULTATION
Start optimizing your IT infrastructure today!