Nova Scotia Power Data Breach: Why Wasn’t Customer Data Deleted? | Cybersecurity Failures Explained (2026)

Nova Scotia Power's recent data breach has raised serious concerns about the security and management of customer information. The company's inability to explain why a digital copy of customer data, stolen in a cyberattack, was not deleted as planned highlights a critical issue in their data handling practices. This incident not only exposes the vulnerability of personal data but also underscores the need for robust security measures and transparent communication in the energy sector.

The breach, which occurred in March 2025, involved the personal data of hundreds of thousands of customers, including addresses, phone numbers, banking information, and social insurance numbers. Nova Scotia Power's vice-president of legal and regulatory affairs, Blake Williams, admitted that the customer information system, launched in 1997, is outdated and susceptible to hacking. This revelation is particularly concerning given the sensitive nature of the data stored.

What makes this incident even more alarming is the company's failure to adhere to its own data retention policies. Nova Scotia Power intended for the data to be automatically deleted within 90 days, but an oversight in the system allowed it to remain accessible to hackers for four years. This oversight not only exposes the company's lack of technical expertise but also raises questions about the effectiveness of their data management practices.

The consequences of this breach are far-reaching. The attack disrupted Nova Scotia Power's automatic billing system, leading to estimated bills that were significantly higher than usual. This not only caused financial strain for customers but also raised concerns about the company's ability to manage its operations effectively. The situation has been further exacerbated by the company's poor communication with customers, which has led to criticism from politicians and calls for a class-action lawsuit.

The Office of the Privacy Commissioner of Canada has also launched an investigation, which resulted in the company's commitment to delete all social insurance numbers from its system. However, this action came after the breach had already occurred, highlighting the company's failure to take proactive measures to protect customer data.

The incident has sparked a broader discussion about the need for improved data security and privacy measures in the energy sector. Nova Scotia Power's inability to explain the oversight in the data deletion process has only added to the public's concerns. The company's reliance on outdated technology and its failure to implement effective data management practices have raised questions about its ability to protect customer information in the future.

In my opinion, this incident serves as a stark reminder of the importance of investing in modern, secure technology and implementing robust data management practices. Nova Scotia Power's failure to do so has not only exposed its customers to potential harm but has also undermined its credibility and trustworthiness. As the energy sector continues to evolve, it is crucial for companies to prioritize data security and privacy to ensure the protection of their customers' sensitive information.

Nova Scotia Power Data Breach: Why Wasn’t Customer Data Deleted? | Cybersecurity Failures Explained (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Sen. Emmett Berge

Last Updated:

Views: 5478

Rating: 5 / 5 (80 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Sen. Emmett Berge

Birthday: 1993-06-17

Address: 787 Elvis Divide, Port Brice, OH 24507-6802

Phone: +9779049645255

Job: Senior Healthcare Specialist

Hobby: Cycling, Model building, Kitesurfing, Origami, Lapidary, Dance, Basketball

Introduction: My name is Sen. Emmett Berge, I am a funny, vast, charming, courageous, enthusiastic, jolly, famous person who loves writing and wants to share my knowledge and understanding with you.