Power Disruption in Data Protection
A Canadian energy provider suspects that some client information may have escaped during a security incident, but they’re remaining tight-lipped about whether the intruders accessed the systems that keep the power flowing.
Customer Data Adrift
London Hydro, the team supplying electricity to more than 160,000 customers in London, Ontario, revealed on Saturday that they are investigating a data security event that “may have affected a segment of personal information on certain accounts.” They are currently reaching out to impacted customers.
The Lost Elements
The data potentially exposed includes names, addresses, email addresses, phone numbers, account and billing information, service locations, pricing plans, contract initiation dates, and meter information. The silver lining? London Hydro confirms that banking details, payment card information, birth dates, government-issued identification numbers, and other sensitive financial data were not involved in the issue.
Anticipation and Quiet
Now, for the less optimistic news: the company is not disclosing much more. Their announcement discusses customer information, but there’s no indication that their operational technology or grid systems were affected. London Hydro has yet to clarify which systems encountered problems, how the situation began, whether data was stolen or merely viewed, or how many individuals have been affected.
Fraudulent Bills and Suspicious Communication
While the haul didn’t snatch bank info, it contains sufficient details to create a convincingly counterfeit utility bill or fake payment request. London Hydro has alerted customers to be wary of fraudulent communications, unexpected bills, unusual account activities, or requests to alter payment arrangements. They’ve also reminded patrons that they never request banking information via email, phone, or SMS.
London Hydro’s Silence
GadgetLad inquired with London Hydro about when they became aware of the breach, whether any data was exfiltrated, how many customers were impacted, if there was any involvement of ransomware or extortion, if third-party systems were affected, and whether operational or grid-related systems suffered damage. There has been no response from London Hydro as of this writing. The company has established a strong barrier around the customer data that may have been exposed. The whereabouts of those attackers or what else they may have tampered with remain unclear.