Globalnews.Ca Nova Scotia Power Data Breach Exposes Data of 900,000 Customers
Article Content
- •Over 900,000 customers affected by the Nova Scotia Power data breach.
- •Breach initiated via malware from a compromised pop-up clicked by an employee.
- •Nova Scotia Power committed to improving security and deleting sensitive data.
A data breach at Nova Scotia Power, discovered on April 25, 2025, compromised sensitive information of over 900,000 customers. The breach initiated when an employee clicked on a malicious pop-up linked to 'SocGholish' malware on March 19, 2025. This allowed attackers to gain access to the network, escalate privileges, and conduct internal reconnaissance. Data was exfiltrated between April 23 and April 25, 2025, followed by ransomware deployment that disrupted services. The breach affected approximately 375,000 current and 540,000 former customers, exposing names, contact information, account details, and Social Insurance Numbers. Nova Scotia Power has since committed to enhancing its security measures and deleting sensitive data. No ransom was paid, and there is no evidence that the stolen data has been sold or publicly released. The Privacy Commissioner of Canada is conducting an ongoing investigation into the incident.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (7)
Following this threat?
Track SocGholish and Nova Scotia Power in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…