Nova Scotia Power confirms theft of customer data in ransomware attack

Organization
Nova Scotia Power
Exploit
Ransomware
Industry
Utilities

Nova Scotia Power, the regulated electric utility serving about half a million customers in the Canadian province and a subsidiary of Emera, confirmed in mid May 2025 that customer information had been stolen during a cyberattack on its corporate network.

The utility said it discovered unauthorised activity on 25 April and announced the incident publicly on 28 April. A forensic investigation established that the intruders first gained access on or around 19 March 2025, giving them roughly five weeks inside the network before detection.

Nova Scotia Power said the stolen records could include names, dates of birth, phone numbers, email addresses, mailing and service addresses, driver's licence numbers, Social Insurance Numbers, and account history covering power consumption, billing, payment and credit information. For customers enrolled in pre-authorised payments, bank account numbers were also involved. Electricity generation, transmission and distribution were not affected, but customer-facing IT systems including the online account portal, billing and payment platforms and outage reporting were disrupted.

The company began notifying affected customers on 14 May and offered a two-year subscription to a credit monitoring service at no cost. It later confirmed the incident was a ransomware attack, said no payment had been made to the attackers in line with sanctions law and law enforcement guidance, and acknowledged that the stolen data had been published. Roughly 280,000 customers were ultimately notified, out of about 550,000 served.

Updates

  1. Nova Scotia Power confirmed the incident was a ransomware attack and said no payment had been made to the threat actor, citing sanctions law and law enforcement guidance. It also said it was sending breach notifications to roughly 280,000 of its approximately 550,000 customers.

Sources