Full Report
Nova Scotia Power revealed that a ransomware attack has prevented meters from sending energy usage data to its systems, impacting billing
Analysis Summary
# Incident Report: Nova Scotia Power Ransomware Attack and Customer Data Breach
## Executive Summary
Nova Scotia Power (NSP) suffered a ransomware cyber incident discovered on April 25, 2025, which disrupted the recording and transmission of customer meter reading data, leading to estimated billing. An investigation confirmed that attackers gained unauthorized access to certain customer data servers around March 19, 2025, leading to the exfiltration of sensitive customer information, including financial details, affecting approximately 280,000 customers. NSP is working with external experts to restore services and is currently issuing estimated bills while working to restore secure system operations.
## Incident Details
- **Discovery Date:** April 25, 2025
- **Incident Date (Data Exfiltration):** Approximately March 19, 2025
- **Affected Organization:** Nova Scotia Power (NSP)
- **Sector:** Utilities (Power/Energy)
- **Geography:** Nova Scotia, Canada
## Timeline of Events
### Initial Access
- **Date/Time:** On or before March 19, 2025
- **Vector:** Undisclosed (implied initial foothold allowing access to customer data servers).
- **Details:** An unauthorized third-party accessed and exfiltrated customer data from specific NSP servers.
### Lateral Movement
- Details are **not provided** in the source material regarding lateral movement post-initial access, beyond the confirmed data exfiltration from customer servers.
### Data Exfiltration/Impact
- **Date/Time:** Around March 19, 2025
- **Impact:** Exfiltration of customer data, including personal and financial details for approximately 280,000 customers.
- **Operational Impact:** Power meters continued to gather energy usage data, but the **ransomware incident prevented this data from communicating to NSP systems**, forcing a temporary pause and subsequent reliance on estimated billing.
### Detection & Response
- **Discovery Date:** April 25, 2025 (Discovery of the cyber incident).
- **Notification:** Authorities were notified on June 6, 2025, regarding the scope of the data breach.
- **Response Actions:** NSP paused billing, engaged external cybersecurity experts, and began issuing estimated bills while working to safely and securely restore systems.
## Attack Methodology
- **Initial Access:** Unknown/Undisclosed.
- **Persistence:** Not detailed.
- **Privilege Escalation:** Not detailed.
- **Defense Evasion:** Not detailed.
- **Credential Access:** Not detailed.
- **Discovery:** Not detailed.
- **Lateral Movement:** Not detailed, though access to specific customer servers was achieved.
- **Collection:** Sensitive customer data (Names, DOBs, contact info, SINs, Driver’s License numbers, banking details) was collected from accessible servers.
- **Exfiltration:** Data was exfiltrated from NSP servers around March 19, 2025.
- **Impact:** Disruption of meter reading data flow (potential ransomware encryption/disruption) and data theft (breach).
## Impact Assessment
- **Financial:** Likely incurred costs related to incident response, forensics, notification, and potential future regulatory fines/remediation. Billing operations were temporarily disrupted.
- **Data Breach:** Yes. Information potentially impacting approximately 280,000 Canadian-based customers, including **Names, Dates of Birth, Phone numbers, Email addresses, Service Addresses, Driver’s License numbers, Canadian Social Insurance Numbers (SINs), and potentially bank account/payment card details.**
- **Operational:** Customer meter readings were blocked from reaching central systems, requiring a shift to estimated billing.
- **Reputational:** Negative impact due to system disruption and exposure of sensitive customer PII/financial data.
## Indicators of Compromise
*Since the source text does not provide specific technical IOCs (IPs, hashes, domains), this section remains generalized based on the known incident type.*
- **Network indicators:** (Not specified)
- **File indicators:** (Not specified, though ransomware activity was present)
- **Behavioral indicators:** Unauthorized access to customer data servers resulting in bulk data transfer and likely disruption of operational technology/billing processes.
## Response Actions
- **Containment:** Efforts initiated immediately upon discovery on April 25, 2025, to stop further unauthorized system access and data loss (though data loss had already occurred by March 19).
- **Eradication:** Ongoing work with external cybersecurity experts to restore systems safely and securely.
- **Recovery:** Transitioning from paused billing to issuing estimated bills while systems are restored for accurate reading reconciliation.
## Lessons Learned
- **Separation of OT/IT Systems:** The incident highlights the risk when operational data collection (metering) is dependent or heavily integrated with potentially vulnerable IT systems, leading to operational service disruptions even if the meters themselves remained functional.
- **Data Minimization:** The compromise of highly sensitive data like SINs and bank details underscores the extreme risk associated with retaining large volumes of PII/financial data in accessible servers.
- **Timely Disclosure:** Data exfiltration occurred in March, but the public confirmation and notification occurred months later (April/June).
## Recommendations
- Implement enhanced network segmentation between meter reading/collection systems and broader corporate IT infrastructure to prevent localized breaches from affecting billing aggregation.
- Review and enhance access controls, monitoring, and auditing on servers containing high-value customer PII and financial data.
- Accelerate ongoing efforts with cybersecurity experts to fully remediate the ransomware impact and restore secure data processing capabilities.