
Nova Scotia Power, the Canadian electric utility serving over half a million customers, has confirmed a ransomware attack that disrupted meter communications and exposed the personal data of approximately 280,000 individuals. While no power outages were reported, the company acknowledged that the breach has impacted both current and former customers, including some in the United States.
In a statement issued Tuesday, Nova Scotia Power said the cyberattack, discovered in April, interfered with the communication between its power meters and internal systems. Although the meters continued to collect accurate energy usage data, the disruption led the company to temporarily pause billing operations. Billing has since resumed, with many customers receiving estimated charges until systems are fully restored.
“Our systems are not yet fully back online,” the utility said. “Most customers are receiving estimated bills until meters begin communicating with our systems again.”
An internal investigation confirmed that the incident was a ransomware attack that resulted in the unauthorized exfiltration of sensitive customer data. Exposed information may include names, dates of birth, email addresses, phone numbers, mailing addresses, power consumption data, payment histories, and, in some cases, driver’s license numbers, Social Insurance Numbers, and bank account details.
While Nova Scotia Power has not identified the threat actor responsible, and no ransomware group has publicly claimed responsibility, the breach appears to have a cross-border impact. The utility’s parent company, Emera, operates electric and gas utilities serving 2.6 million customers throughout North America, including the United States.
According to a disclosure submitted to the Maine Attorney General’s Office, 377 residents of Maine were among those affected. The total number of U.S. individuals impacted by the breach has not been confirmed.
Nova Scotia Power has begun notifying affected individuals and is offering support through its website. The company emphasized that the cyberattack did not compromise the delivery of electricity or critical infrastructure.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543