NS Power can’t explain why hacked customer data was not deleted as planned

August 19, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: ctvnews.ca

Threat Risk: High
Victim: Utility Provider
Incident: Data breach of over 370,000 customers via a compromised cloud backup.
Impact: Theft of banking information, social insurance numbers, and disruption of automated billing systems.
Attacker: Russia-based threat actors
Analysis: Threat actors leveraged phishing to breach a Microsoft Azure instance containing outdated customer records that failed to auto-delete. This incident highlights a critical failure in data lifecycle management, where sensitive PII was retained years beyond its intended lifespan. The resulting ‘shadow data’ created a high-value target that existed outside the primary system’s security controls.
Recommendations: Implement and strictly audit automated data retention and deletion policies.; Perform regular discovery scans to identify and purge orphaned data copies in cloud environments.; Deploy phishing-resistant multi-factor authentication to protect cloud administrative access.
Source: CTV News / The Canadian Press

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *