Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Incident Response

Canadian Electric Utility Hit by Cyberattack

Nova Scotia Power and Emera are responding to a cybersecurity incident that impacted IT systems and networks. 

Electric utility hacked

Canadian electric utility Nova Scotia Power and its parent company Emera are responding to a disruptive cyberattack.

The attack came to light on April 25, when Emera and Nova Scotia Power discovered unauthorized access to some parts of their Canadian network and servers used for business applications. Impacted servers were shut down and isolated in response to the hack. 

IT systems, including the utility’s customer care phone line and online portal, were disrupted. The company has not shared any updates on the incident since April 28, when it said it had been working on restoring impacted systems.

Nova Scotia Power provides electrical power to roughly 550,000 customers. Emera, through its electric and natural gas utilities, serves 2.6 million customers in Canada, the US and the Caribbean.

However, the companies said the cyberattack did not cause any power outages. 

“There remains no disruption to any of our Canadian physical operations, including at Nova Scotia Power’s generation, transmission and distribution facilities, the Maritime Link or the Brunswick Pipeline, and the incident has not impacted the utility’s ability to safely and reliably serve customers in Nova Scotia,” the companies said in a statement. “There has been no impact to Emera’s US or Caribbean utilities.”

Advertisement. Scroll to continue reading.

Nova Scotia Power is investigating whether any customer or confidential business information was compromised as a result of the incident. 

It would not be surprising to learn that the power company has been targeted in a ransomware attack, but at the time of writing no known ransomware group appears to have taken credit for the intrusion.

SecurityWeek has reached out to Nova Scotia Power for more information and will update this article if the company responds.

Energy companies are often targeted by threat actors, including profit-driven cybercriminals and state-sponsored groups. One incident that came to light recently involved the Chinese hacker group Volt Typhoon, which had access to the US electric grid for 300 days in 2023. 

Related: More Solar System Vulnerabilities Expose Power Grids to Hacking

Related: Siemens Patches Power Grid Product Flaw Allowing Backdoor Deployment

Related: China-Linked ‘Redfly’ Group Targeted Power Grid

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Jonathan Trull has joined Oracle as Global Head of Cyber Defense.

Plaid has appointed Sean Cassidy as Chief Information Security Officer.

Ann Barron-DiCamillo has been named Executive Vice President and Global Chief Information Security Officer at U.S. Bank.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.