A new report from Nova Scotia Power lays out the timeline and extent of the cyberattack last spring and it notes all customers may have been impacted by the security breach. The power utility filed the report at the request of the Nova Scotia Energy Board, which is investigating the March cyberattack. The board filed several questions it wanted answered by mid-August, but it granted the utility an extension to early September. “These information requests seek information frequently requested by NS Power’s customers in their letters and emails to the Board expressing concerns, frustrations, and complaints about the compromise and misuse of their personal information, the risks relating to the release of their personal information, and difficulties encountered in communications with the credit monitoring service engaged by NS Power,” a previous letter from the board reads. The report says Nova Scotia Power notified roughly 277,000 customers they had been impacted by the cybersecurity breach, but it notes the scope of the attack is still under investigation. “It remains possible that all of the Company’s customers may have been impacted by the cyber attack,” it says. “The Company will send letters about the incident to other active customers it identifies as being impacted.” The report says the billing of customers was impacted by the breach and they have been working to fully restore the service. In June the utility began issuing estimated bills based on an average of previous energy used at a property at the same time last year. “Some customer bills did appear larger than anticipated, and there were a variety of reasons for this,” the report reads. “In some cases, payments had not yet been received and processed; some customers received bills closer together as NS Power caught up on billing after the pause from April 2 25-June 4; and estimated bills mean that changes customers have made at the premises may not be reflected. “Customers will never pay for power they do not use. Any under- or over-payment will be addressed and accurately reflected on a future bill. Also, the Company has not applied late charges, or penalties on any outstanding balances since the incident.” Timeline Nova Scotia Power says the “sophisticated and coordinated cyberattack” happened on or around March 19, but the utility didn’t detect it until April 25 when they found certain applications on their systems were not functional. “Upon immediate investigation, it became evident that a threat actor had gained unauthorized access into certain parts of NS Power’s information technology network and servers which support portions of its business applications,” the report reads. “On May 1, 2025, NS Power determined that customer information had been impacted in the Incident, and promptly updated customers to inform them that they had identified that certain customer personal information had been impacted in the Incident, and again encouraged them to remain vigilant and cautious of unsolicited communications and potential scams.” Nova Scotia Power determined some of the stolen information was published on the dark web, which is known to be used by criminals to trade data. The utility previously said it will delete the social insurance numbers of all its customers from its files. The Office of the Privacy Commissioner of Canada launched an investigation into the incident on May 28. Credit monitoring Nova Scotia Power is offering a free, five-year credit monitoring service through TransUnion for impacted customers. The service includes unlimited online access, dark web monitoring and up to $1 million of expense reimbursement insurance related to identity theft. The utility notes some customers had trouble signing up for the service online, so it updated its website with tips and held more than 30 in-person sessions in communities. “The vast majority of individuals were able to complete the online enrollment process within a few minutes using their activation code,” the report reads. For more Nova Scotia news, visit our dedicated provincial page