Nova Scotia Power says it appears the hackers behind a recent cybersecurity breach also accessed the personal information of former customers. As a result, the utility is now offering five years of free credit monitoring to all customers – both past and present – whether or not they received a letter about the cybersecurity breach. “We have determined through our investigation that the personal information of former customers was also accessed on or around March 19, 2025, and later taken by an unauthorized third party, in addition to the personal information of the current customers to whom notifications have already been sent,” said Nova Scotia Power in a statement Wednesday. “Customers will not pay for any costs incurred by Nova Scotia Power for credit monitoring resulting from this incident.” The utility previously said 280,000 customers were affected by the breach. Nova Scotia Power says a dedicated team within the utility is working with third-party cybersecurity experts to investigate the ransomware attack. It says the personal information of former customers, including names, phone numbers, email address and mailing addresses, may have been compromised. “For some of our former customers, bank account numbers (for pre-authorized payment) and Social Insurance Numbers may also have been impacted,” said the utility. “We intend to do everything we can to support current and former customers, which includes expanded access to credit monitoring.” Anyone who has already signed up for credit monitoring will automatically be extended to receive the service for five years. Former and current customers who wish to sign up for the credit monitoring service can go online to validate and secure a unique code. Nova Scotia Power said it’s also deploying employee volunteers to communities across the province to provide support for customers who prefer assistance in person. “Some of our back office systems were impacted in the cyberattack,” said Jacqueline Foster, spokesperson with Nova Scotia Power. “We are actively working to restore our systems and continuing to expand our interim business processes where needed to ensure business continuity to serve our customers.” Nova Scotia Power will delete all SINs The utility says people have expressed concerns about having social insurance numbers (SINs) on file, so it will be deleting that information from its systems. “We have heard concerns about SINs, which we historically collected for customer authentication purposes,” said Nova Scotia Power. “We are committed to permanently deleting all instances of SINs from our systems as soon as our investigation allows.” Timeline of breach Nova Scotia Power said it detected “unusual activity” on its network on April 25 and immediately initiated an incident response plan, which included launching its own investigation and contacting law enforcement. Nova Scotia Power informed the public about the incident three days later, on April 28. After further investigation, on May 14 the utility confirmed the breach happened on or around March 19, when an unauthorized third party accessed and stole certain customer information stored on the impacted servers. On May 23, Nova Scotia Power confirmed the breach was the result of a “sophisticated ransomware attack” but that no payment had been made to the hackers. It also warned that the hackers had published the stolen data. Nova Scotia Power has apologized for the breach and says it’s continuing to take steps to understand how it happened and how to prevent it from happening again. “We recognize that this incident may have shaken the confidence of some of our customers,” said the utility. “We are working hard to do everything we can to regain your confidence.” The Office of the Privacy Commissioner of Canada and the Nova Scotia Energy Board are also investigating the incident. -With files from CTV News Atlantic’s Hafsa Arif For more Nova Scotia news, visit our dedicated provincial page