← All news

breach

London Hydro Confirms Breach, Stays Quiet on the Details

2026-06-22

London Hydro, the utility that keeps the lights on for more than 160,000 customers around London, Ontario, has confirmed that customer data may have been exposed in a security incident. Almost everything else about the incident remains unconfirmed.

In a statement issued on Saturday, the utility said the data potentially caught up in the breach includes names, postal and email addresses, phone numbers, account and billing numbers, service addresses, pricing plans, contract start dates and meter information. Banking details, payment card numbers, dates of birth and government-issued IDs were not involved, according to the company.

A lot of unanswered questions

That's where the clarity ends. London Hydro hasn't said when the intrusion was discovered, how attackers got in, how many customers were affected, or whether data was actually exfiltrated or merely accessed. There's no mention of ransomware, and no comment on whether operational technology or grid systems were touched. The statement doesn't explicitly rule that out either. The Register put all of these questions to the utility and got no response.

That silence is doing a lot of work. Utilities sit in a category of organisation where the difference between "some customer records were viewed" and "an attacker had a foothold in systems that control physical infrastructure" is enormous. Customers and regulators are entitled to know which side of that line this incident sits on.

Why the leaked data matters

The information London Hydro has confirmed was exposed is, on its own, the sort of detail that makes social engineering considerably easier. Consider what an attacker now potentially holds for an affected customer:

  • Account and billing numbers that appear on real correspondence from the utility.
  • Service addresses and pricing plans that let a caller sound like they're reading from a genuine customer record.
  • Contract start dates and meter information that almost no one outside the utility would plausibly know.

Put those together and you have everything you need to build a convincing fake bill, send a believable arrears notice, or place a phone call from "customer service" asking to update payment arrangements because of a billing system issue. The fact that no banking or card data leaked is genuinely good news, but it's also slightly beside the point. The leaked data is the setup. The bank details are what the attacker now tries to coax out of the customer directly.

London Hydro has, to its credit, told customers to be on the lookout for exactly that kind of approach, and reminded them that the utility doesn't ask for banking details by email, phone or text. That's the right advice, but it's also the advice that suddenly matters a great deal more this week than it did last week.

The shape of what we don't know

What's striking about the statement is how cleanly the company has drawn a line around the customer information it's willing to discuss. Inside the line: a tidy list of data fields, a reassurance about what wasn't taken, and some sensible warnings. Outside the line: the actual story of what happened, when, and how bad it really was.

For affected customers, the practical posture is straightforward. Treat any unexpected communication that references your London Hydro account with suspicion, even if it cites information that only the utility should know. That assumption used to be a reasonable shortcut. For the time being, it isn't.

London Hydro Confirms Breach, Stays Quiet on the Details | RiskSense