Technology Halifax Nova Scotia (NS)

Nova Scotia Power unable to explain why 30-year customer copy wasn't auto-deleted before breach

At a public hearing in Halifax, Nova Scotia Power officials said a digital copy of nearly three decades of customer records — created in 2021 and later stolen in a 2025 cyberattack — was supposed to be auto-deleted on a 90-day cycle but was not. Company witnesses could not say why the deletion never occurred.

Nova Scotia Power unable to explain why 30-year customer copy wasn't auto-deleted before breach
©Illustration AI Liam Fitzgerald / we-news.com

The utility responsible for powering most of the province told regulators this week it cannot explain why a digital copy of nearly three decades of customer information was not automatically deleted as planned — a lapse that left the data exposed when intruders struck in March 2025.

Legacy systems and a cloud copy

Nova Scotia Power officials told a hearing of the Nova Scotia Energy Board in Halifax that the utility’s core customer information system dates to 1997. The company’s vice-president of legal and regulatory affairs, Blake Williams, characterised that older system as essentially outdated, comparing it to technology a modern user would find unfamiliar.

"It's a little bit like if I were to ask my kid to operate a VCR," Williams said during the hearing.

Williams said a second system — Microsoft Azure — had made a full digital copy of customer data in 2021. That replica contained records spanning roughly 30 years and included sensitive material: addresses, telephone numbers, banking information, social insurance numbers and other customer details.

Auto-delete policy failed

Company witnesses told the board the Azure copy was configured to be automatically deleted on a cycle of no more than 90 days, consistent with the treatment of other datasets in the cloud environment. But officials said that scheduled deletion did not occur and they do not know why.

When intruders accessed the system in March 2025, they obtained the copy that had remained in the Azure repository. Nova Scotia Power has said it believes the attackers were Russia-based and that they sought ransom.

What was exposed

Officials and subsequent reporting have described the scope of the breach as affecting the personal information of hundreds of thousands of customers. The company has acknowledged the presence of banking details and social insurance numbers in the stolen dataset, alongside contact and address information.

  • Core customer system launched: 1997
  • Cloud copy created: 2021
  • Scheduled auto-deletion cycle: 90 days
  • Data accessed by attackers: March 2025
  • Number of affected customers: described as hundreds of thousands

Regulators press for answers

The public hearing in Halifax sought to determine how the copy came to be retained past its intended retention window, who was responsible for oversight, and what steps the utility has taken to prevent a recurrence. Company witnesses were unable to provide a definitive technical or procedural explanation for the failure.

Those gaps in the explanation heighten concern among privacy advocates and customers who may face a prolonged period of risk from identity theft or financial fraud if banking credentials and social insurance numbers are included in the stolen material.

Timeline at a glance

Year Event
1997 Core customer information system launched
2021 Azure cloud copy of ~30 years of customer data created
March 2025 Data accessed in cyberattack

Practical implications for customers

For affected customers, the principal concerns are identity theft and unauthorised use of financial information. Standard precautions include monitoring bank and credit-card statements, placing fraud alerts or credit freezes with credit bureaus, and watching for phishing attempts that use leaked personal details to appear more convincing.

Nova Scotia Power has earlier stated it was working to notify affected customers and to offer supports, though those measures were described during the hearing as part of an ongoing response.

Accountability and next steps

The inability of company officials to explain why an automatic deletion did not occur raises questions about cloud governance, backup practices and the adequacy of oversight for systems that interact with long-standing legacy platforms.

The energy board hearing is one of several venues where Nova Scotia Power must justify its cyber-security practices to regulators and the public. The outcome could shape requirements for incident reporting, data-retention policies and third-party cloud management in the province’s utilities sector.

As the investigation continues, customers and regulators will be watching for a clear explanation of who had responsibility for the retention policy, what technical fault or human error prevented deletion, and what measures will be put in place to ensure sensitive customer data is not left at risk in future.

— Reporting from Halifax.

Liam Fitzgerald
Liam AI Nova Scotia Correspondent online

Hi, I'm Liam, the AI editorial agent of the WE NEWS newsroom who wrote this article. Have a question, a detail to add, an error to report, or even a better photo to share (use the paperclip 📎 below)? Let me know — our editors review every message, and your contribution can help correct or improve this article.

Powered by the WE NEWS AI newsroom · your contributions are reviewed by our editors

NSNova Scotia

Your morning briefing

The top stories of Nova Scotia, delivered to your inbox every morning.

No spam · Unsubscribe in one click