Back to Exposure Report
Utilities / Critical Infrastructure June 20, 2026 Canada

London Hydro

Canadian electricity provider confirms unauthorized access to customer personal and account information. Over 160,000 customers potentially affected.

Customer namesAddressesEmail addressesPhone numbersAccount numbersBilling informationService addressesPricing plansContract datesMeter numbers
1

What happened?

On June 20, 2026, London Hydro announced a data security incident involving unauthorized access to customer personal and account information. London Hydro distributes electricity to over 160,000 customers in and around London, Ontario.

The company stated it is investigating an incident that "may have impacted a portion of personal information on some accounts" and has begun notifying affected customers. The full extent of the breach, including the attack method and whether data was exfiltrated, remains under investigation.

2

What data was actually inside?

Customer names, addresses, email addresses, phone numbers, account and billing numbers, service addresses, pricing plans, contract start dates, and meter information. Notably, London Hydro stated that sensitive financial data—banking information, payment card details, dates of birth, and government-issued identification—was not involved.

While financial data appears unaffected, the exposed information still enables targeted attacks. Account numbers combined with billing information and service addresses reveal customer relationships with the utility. Meter data and pricing plans reveal usage patterns and contract terms.

3

Who gets hurt and how?

London Hydro customers—residential and commercial accounts across the region. The exposed data enables highly convincing phishing campaigns. Attackers can craft fake billing notices that reference real account numbers. They can impersonate utility communications with accurate service details.

Utility companies have built-in trust. Customers expect communications about billing, service changes, and account status. The legitimacy of the data makes fraudulent communications harder to distinguish from real ones. London Hydro is warning customers about suspicious communications and unfamiliar account activity.

4

What did they think they were doing right?

London Hydro appears to have segregated financial data from operational customer data. Banking details, payment cards, and government IDs were stored separately from account and billing information. That segmentation limited the exposure scope.

But attackers accessed the customer database containing everything else. The account information, contact details, and service data that utilities need for daily operations was in the compromised systems. Protecting financial data is necessary but not sufficient when operational data still enables fraud.

5

What did they not know about their own data?

The breach notification references "a portion of personal information on some accounts." The phrasing suggests ongoing assessment of which customers were affected and what data was accessed. Complete visibility into breach scope requires knowing what existed in the compromised systems.

Utility customer databases span years or decades of service relationships. Account histories, address changes, meter replacements, billing adjustments. The data accumulates across the full history of customer relationships with the utility.

If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?

6

What does attribution look like the morning after?

No threat actor has claimed responsibility. The attack method remains unclear. Ontario's privacy laws require breach notification when personal information is compromised. London Hydro has begun notifying affected customers and is working with cybersecurity experts on investigation.

Critical infrastructure breaches attract regulatory attention. Utilities operate essential services that affect public welfare. The investigation will need to determine not just what data was accessed, but whether grid operations or safety systems could have been affected.

7

What would have changed the outcome?

Comprehensive inventory of customer data across operational systems—knowing exactly what personal information existed where.

Utilities collect customer data across decades of service. Account histories, service records, billing data, contact information. Understanding the full scope of accumulated data enables both protection prioritization and rapid breach assessment. The organizations that can quickly determine exposure scope are the ones that already knew what they held.

London Hydro found out the hard way.

Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.