Nova Scotia Power has pledged to delete all social insurance numbers (SINs) from its systems and to submit an external security assessment in response to last year’s cyberattack that impacted more than 900,000 current and former customers. The Office of the Privacy Commissioner of Canada, which launched a review of the data breach following multiple complaints, said Nova Scotia Power has promised to provide them with a security assessment and review on their information technology’s enhanced safeguards by Oct. 31. The report, which will be conducted by an external firm, will detail: Nova Scotia Power has also committed to deleting all customer SINs from its systems by the end of the month. Birth dates and SINs were potentially impacted by the data breach last year. In a redacted report issued last December, Nova Scotia Power said it collected SINs from customers as part of its authentication process before 2018, but changed that practice and started purging them from their system in May 2024. “I welcome this commitment by Nova Scotia Power to ensure stronger protections for the personal information of its customers,” said Philippe Dufresne, privacy commissioner of Canada, in a news release. “This privacy breach highlights the significant risks of cyberattacks to individuals and companies. Strong, proactive data protection, including robust safeguards, must be prioritized by all organizations in this evolving landscape.” Timeline of cyberattack According to the Office of the Privacy Commissioner, a Nova Scotia Power employee clicked on a link in a pop-up on a site that had been compromised by the “SocGholish” malware on or around March 19, 2025. The malware was downloaded and installed on the utility’s systems and created a background process that allowed a threat actor access to the network. Between April 8 and 22, the threat actor deployed additional malware and then exfiltrated data from network files and cloud storage. On April 25, the threat actor destroyed backups and deployed malware. Nova Scotia Power detected the breach on April 25, but did not inform the public of it until early May. “Nova Scotia Power received communications from the threat actor that included a hyperlink to an unlisted page accessible through the Tor network on the dark web,” the Office of the Privacy Commissioner says. “The threat actor provided proof that it had obtained sensitive customer information, but no evidence has yet emerged that this sensitive data has been made public or sold. “After its assessment of applicable sanctions laws and alignment with law enforcement guidance, Nova Scotia Power did not pay a ransom to the threat actor.” The utility notified the RCMP, the Canadian Security Intelligence Service and the Federal Bureau of Investigation about the breach. They later determined roughly 375,000 current and 540,000 former customers were affected by the incident. The compromised personal information could have included names, phone numbers, email addresses and driver’s licence numbers. “While the cyberattack did not affect our ability to generate or deliver energy, it did severely disrupt several internal systems, including our customers’ billing experiences,” Nova Scotia Power said in a news release. “Meters continued to function accurately, but the malware prevented us from receiving data about energy usage. “Most meters have now been reconnected to our digital billing system, and the plan is on track to reconnect the remaining meters by March 31, 2026. As of the end of February, less than 10% of customers were still getting an estimated bill.” The Nova Scotia Energy Board said it is conducting a two-part inquiry into the cyberattack. With files from The Canadian Press For more Nova Scotia news, visit our dedicated provincial page