Nova Scotia Power says it’s made “significant enhancements” to its cybersecurity since the March 2025 cyberattack that impacted hundreds of thousands of customers and resulted in the organization purging all social insurance numbers (SINs) from its systems. The utility will discuss those enhancements and the ongoing billing issues for customers at a Nova Scotia Energy Board public hearing on Tuesday. Premier Tim Houston called on the board to investigate Nova Scotia Power’s billing process last December. “Customers should not be paying for NSP’s failures,” Houston said in an open letter. “The cyberattack was not the fault of Nova Scotians, yet they are bearing the financial consequences of NSP’s operational shortcomings.” The hearing will be held at 1601 Lower Water St. at 9 a.m. on Tuesday. It will go until Thursday if needed. Restoring systems In a written statement, Lia MacDonald, senior vice president of technology with Nova Scotia Power, said they recognize the “concern, frustration, and uncertainty” the cyberattack caused. “Since the Attack, our focus has been on restoring systems safely and securely while strengthening our cybersecurity and privacy posture,” MacDonald said. “We are pleased to report that major systems have been restored, and Nova Scotia Power has returned to normal operations across most of the areas of the business. Nova Scotia Power has also implemented significant enhancements to its cybersecurity and privacy posture. “We are committed not only to recovering from this incident, but to restoring confidence, learning from what occurred, and emerging as a stronger and more secure organization for our customers, employees, and communities.” The Office of the Privacy Commissioner of Canada reviewed multiple complaints about the data breach and said Nova Scotia Power has pledged to provide a security assessment by Oct. 31. Earlier this year, the utility said roughly 375,000 current and 540,000 former customers were impacted by the cyberattack, which compromised personal information like names, birth dates, phone numbers and email addresses. Nova Scotia Power also revealed SINs could have been compromised in the breach. It noted it collected SINs as part of its authentication practice before 2018, but later changed it and started deleting them from their system in March 2024. The utility said it purged all SINs from its system last April. History of cyberattack According to the Office of Privacy Commissioner, the malware “SocGholish” was downloaded and installed on Nova Scotia Power’s system after an employee clicked on a link in a pop-up on a site on or around March 19, 2025. The malware then created a background process that allowed a threat actor access to the network. From April 8 to 22, the threat actor deployed additional malware and exfiltrated data from network files and cloud storage. On April 25 they destroyed backups. Nova Scotia Power detected the breach that day, but did not inform the public about it until early May. “Nova Scotia Power received communications from the threat actor that included a hyperlink to an unlisted page accessible through the Tor network on the dark web,” the Office of the Privacy Commissioner says. “The threat actor provided proof that it had obtained sensitive customer information, but no evidence has yet emerged that this sensitive data has been made public or sold. “After its assessment of applicable sanctions laws and alignment with law enforcement guidance, Nova Scotia Power did not pay a ransom to the threat actor.” Nova Scotia Power previously noted the cyberattack disrupted several internal systems, including customer billing. The malware prevented them from receiving data about energy usage from meters, which caused the company to rely on estimated bills. By the end of last February, fewer than 10 per cent of customers were still receiving estimated bills. For more Nova Scotia news, visit our dedicated provincial page