Canada’s privacy commissioner is calling for stronger data protections at Nova Scotia Power following a major cyberattack in 2025 that exposed the personal information of hundreds of thousands of customers. In a statement, Privacy Commissioner Philippe Dufresne said his office is focused on ensuring personal information is better protected after a breach that impacted roughly 900,000 current and former customers. Nova Scotia Power has committed to providing an independent external security assessment by Oct. 31, 2026. The report will outline improvements made since the breach, identify any remaining gaps and include a plan to address them. Dufresne said the commitment is a positive step, but warned the breach highlights the growing risks cyberattacks pose to individuals and organizations, stressing that stronger, proactive safeguards must be a priority. According to a compliance letter submitted to the Office of the Privacy Commissioner of Canada, the breach began around March 19, 2025, when an employee unknowingly downloaded malware from a compromised website. The malicious software allowed a threat actor to gain access to the company’s network. On April 25, the attacker deployed ransomware and destroyed backups, prompting employees to report system failures that led to the discovery of the breach. Nova Scotia Power said it later received proof from the attacker that sensitive customer information had been obtained, though there is no evidence the data has been made public or sold. The company said it did not pay a ransom. Cybersecurity expert David Shipley said the commissioner’s findings provide clarity about how the breach unfolded, pointing to a malicious pop-up as the starting point. He said these incidents increasingly common and underscore how easily organizations can be compromised, adding that public awareness can help reduce risk. But Shipley also criticized Canada’s privacy framework, saying there are limited consequences for companies following major breaches. “There are no consequences in this country for massive failures like this,” he said, adding that stronger laws and penalties could push organizations to invest more in prevention. Nova Scotia Power said it will delete customer social insurance numbers from its systems where possible and strengthen safeguards as part of its commitment. The company must also report on the effectiveness of its security measures, employee training and breach notification processes as part of the external review. A proposed class-action lawsuit filed on behalf of affected customers is proceeding separately from the federal privacy investigation. Dalhousie University law professor Wayne MacKay said the two processes serve different purposes. “One is the privacy commissioner process… the other is the class action seeking compensation for victims,” he said. MacKay said compliance with the commissioner’s recommendations could improve the company’s standing but would not eliminate potential liability for damages caused by the breach. He added that while the commissioner can require further action or monitoring, the office does not award compensation, leaving that to the courts through civil litigation. Experts say the long-term impact of the breach will depend not only on how Nova Scotia Power responds, but also on whether governments strengthen privacy laws to prevent similar incidents in the future. Nova Scotia Power has said customers should continue monitoring their financial information for any unusual activity. For more Nova Scotia news, visit our dedicated provincial page