Nova Scotia Power officials say they don’t know why a digital copy of almost three decades worth of customer information that was later stolen in a cyberattack was not automatically deleted as intended.
The information, containing the personal data of hundreds of thousands of customers, was accessed in March 2025 by what the company has said it believes were Russia-based actors.
Get breaking National news
It contained addresses, phone numbers, banking information, social insurance numbers and other customer data.
Executive Blake Williams told a regulatory hearing that the company has mechanisms to automatically delete certain data in cycles of no more than 90 days.
- Governor General calls for ‘concrete action’ on Truth and Reconciliation Day
- Mary Louie recalls leaving residential school and why her band marks Orange Shirt Day a day early
- Nearly dozen of Winnipeg school trustees acclaimed ahead of election
- Edmonton condo owners accuse investment firms of ‘predatory’ takeovers
He said the utility does not know why the file, created in 2021 and still present in the system in 2025, was never deleted.
If it had been destroyed as intended, Williams says the information would not have been available to the attackers.
Comments
Want to discuss? Please read our Commenting Policy first.