The utility responsible for powering most of the province told regulators this week it cannot explain why a digital copy of nearly three decades of customer information was not automatically deleted as planned — a lapse that left the data exposed when intruders struck in March 2025.
Legacy systems and a cloud copy
Nova Scotia Power officials told a hearing of the Nova Scotia Energy Board in Halifax that the utility’s core customer information system dates to 1997. The company’s vice-president of legal and regulatory affairs, Blake Williams, characterised that older system as essentially outdated, comparing it to technology a modern user would find unfamiliar.
"It's a little bit like if I were to ask my kid to operate a VCR," Williams said during the hearing.
Williams said a second system — Microsoft Azure — had made a full digital copy of customer data in 2021. That replica contained records spanning roughly 30 years and included sensitive material: addresses, telephone numbers, banking information, social insurance numbers and other customer details.
Auto-delete policy failed
Company witnesses told the board the Azure copy was configured to be automatically deleted on a cycle of no more than 90 days, consistent with the treatment of other datasets in the cloud environment. But officials said that scheduled deletion did not occur and they do not know why.
When intruders accessed the system in March 2025, they obtained the copy that had remained in the Azure repository. Nova Scotia Power has said it believes the attackers were Russia-based and that they sought ransom.
What was exposed
Officials and subsequent reporting have described the scope of the breach as affecting the personal information of hundreds of thousands of customers. The company has acknowledged the presence of banking details and social insurance numbers in the stolen dataset, alongside contact and address information.
- Core customer system launched: 1997
- Cloud copy created: 2021
- Scheduled auto-deletion cycle: 90 days
- Data accessed by attackers: March 2025
- Number of affected customers: described as hundreds of thousands
Regulators press for answers
The public hearing in Halifax sought to determine how the copy came to be retained past its intended retention window, who was responsible for oversight, and what steps the utility has taken to prevent a recurrence. Company witnesses were unable to provide a definitive technical or procedural explanation for the failure.
Those gaps in the explanation heighten concern among privacy advocates and customers who may face a prolonged period of risk from identity theft or financial fraud if banking credentials and social insurance numbers are included in the stolen material.
Timeline at a glance
| Year | Event |
|---|---|
| 1997 | Core customer information system launched |
| 2021 | Azure cloud copy of ~30 years of customer data created |
| March 2025 | Data accessed in cyberattack |
Practical implications for customers
For affected customers, the principal concerns are identity theft and unauthorised use of financial information. Standard precautions include monitoring bank and credit-card statements, placing fraud alerts or credit freezes with credit bureaus, and watching for phishing attempts that use leaked personal details to appear more convincing.
Nova Scotia Power has earlier stated it was working to notify affected customers and to offer supports, though those measures were described during the hearing as part of an ongoing response.
Accountability and next steps
The inability of company officials to explain why an automatic deletion did not occur raises questions about cloud governance, backup practices and the adequacy of oversight for systems that interact with long-standing legacy platforms.
The energy board hearing is one of several venues where Nova Scotia Power must justify its cyber-security practices to regulators and the public. The outcome could shape requirements for incident reporting, data-retention policies and third-party cloud management in the province’s utilities sector.
As the investigation continues, customers and regulators will be watching for a clear explanation of who had responsibility for the retention policy, what technical fault or human error prevented deletion, and what measures will be put in place to ensure sensitive customer data is not left at risk in future.
— Reporting from Halifax.