London Hydro sent out an email to customers on Friday night, notifying them of a data breach that could have leaked personal information. Information potentially impacted includes contact information, which includes full name, address, email address, phone number, and account information, which includes account/billing number, service address, pricing, plan, contract details, and meter numbers/details. “There was no access to any sensitive personal information as a result of this incident, such as your date of birth, government identification number, payment card details, or banking information,” the statement read. In a statement to CTV News, London Hydro CEO, Ysni Semsedini, said after the company became aware of suspicious activity on a customer account Friday, an investigation was instantly launched. “We have determined that the account was used to exploit a system vulnerability, which allowed access to certain information about other customers,” said Semsedini. “This matter will not impact service delivery to our customers. We are taking the situation seriously. The issue that allowed an unauthorized person to access customer information was fixed on the same day that it was discovered, and we have taken additional steps to prevent further issues.” London Hydro continues to try and gather as much information as possible. The investigation is working with London police and said no further details can be provided at this time. “This seems to have become a daily thing, a regular drumbeat of companies advising customers of yet another cybersecurity incident. It’s no longer a matter of if a breach will happen to any given organization, but when,” said Carmi Levy, technology analyst. “The good news, if there can actually be any in a case like this, is that the breached data is limited to contact information. So, while the risk of bad actors using this information to directly compromise victims is relatively low – because they didn’t get usernames and passwords this time – it’s entirely likely that affected customers might notice an uptick in identity theft attempts and other kinds of phishing messages in their inbox.” Levy added that London Hydro is sharing a reasonable level of detail about the risks faced for customers. It is not known at this time how the breach happened, what they are doing to prevent it from happening again, and how customers will be compensated as a result. “In the meantime, news of this breach should service as a reminder to London Hydro customers and the general population alike that we could always be doing more to tighten our own personal digital security,” Levy added. “Adding two or multi-factor authentication to our accounts using smart password protocols, activating encryption, and reducing our sharing on social media can help minimize our risk of being targeted in the first place, and limiting the damage in case we get caught on the wrong side of a cyberattack.” London Hydro says it will continue to update customers via notices on its website as it gains more information it is able to share. “We know that our customers may be frustrated or anxious, which is why we are acting as fast as we can to address the situation and communicate with you,” the company wrote on X. “Please know we care about your concerns and your privacy, and we are working hard to resolve this matter.” Levy added that while this can be startling, London is not at imminent risk of being directly attacked. “However, their risk profile is higher than it has been because now, more information is out there. What they should be doing is watching their inboxes for increased outreach from cyber criminals,” he said. “They will be seeing more messages trying to get them to click on a link, trying to convince them that they are, in fact, from London Hydro, when they are not.” If you receive an unsolicited message in your email inbox or social media, Levy recommends contacting the company directly through a known phone number. If you are worried something is a phishing scam, log onto an actual computer, not a touch screen device, and use your mouse to hover over any links to ensure it is a legitimate website. He also recommended to limit what you share on social media, keeping private information that could help hackers off your page. “Just about every company that we deal with in our day-to-day lives at some point will be targeted,” he said. “Now is not the time to assign fault. We await more news from London Hydro on what happens and what they’re doing to minimize risk going forward. In the meantime, focus on your own personal security. Tighten the things that you can tighten, and move on with your life.”