Skip to content
Nova Scotia Power Data Breach Exposes Data of 900,000 Customers

Nova Scotia Power Data Breach Exposes Data of 900,000 Customers

First seen 25 Mar 2026, 18:47 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 26, 2026 at 18:18 UTC

A data breach at Nova Scotia Power, discovered on April 25, 2025, compromised sensitive information of over 900,000 customers. The breach initiated when an employee clicked on a malicious pop-up linked to 'SocGholish' malware on March 19, 2025. This allowed attackers to gain access to the network, escalate privileges, and conduct internal reconnaissance. Data was exfiltrated between April 23 and April 25, 2025, followed by ransomware deployment that disrupted services. The breach affected approximately 375,000 current and 540,000 former customers, exposing names, contact information, account details, and Social Insurance Numbers. Nova Scotia Power has since committed to enhancing its security measures and deleting sensitive data. No ransom was paid, and there is no evidence that the stolen data has been sold or publicly released. The Privacy Commissioner of Canada is conducting an ongoing investigation into the incident.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 198d ago How this analysis works

Timeline

2025-03-19
Employee clicked on a malicious pop-up, initiating the breach.
2025-04-08
Attackers began moving laterally across systems.
2025-04-23
Data exfiltration occurred before ransomware deployment.
2025-04-25
Breach discovered by Nova Scotia Power.
2026-03-26
Nova Scotia Power commits to stronger security measures.

More articles in this cluster (7)

Following this threat?

Track SocGholish and Nova Scotia Power in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed