Saturday, October 3, 2026
HomeLocalHalifax Water Maintains Paper Billing Amid Privacy Breach

Halifax Water Maintains Paper Billing Amid Privacy Breach

Date:

Halifax Water has decided to maintain paper billing services for its customers as the organization works on resolving a recent privacy breach that impacted 16 accounts. The utility’s online portal for accessing bills has been inaccessible since March, following the discovery of a security vulnerability by third-party cybersecurity experts.

According to a recent update, an investigation revealed that the breach occurred due to a flaw in the third-party platform supporting the Customer Connect portal, which allowed an external entity to access personal details linked to the affected accounts. The incident did not involve any breach of Halifax Water’s operational systems related to water and wastewater services.

The compromised information from the 16 accounts included customer names, email addresses, service or home addresses, account details, and security questions and answers. Fortunately, no financial data was compromised.

The CEO of Halifax Water, Kenda MacKenzie, expressed regret over the incident and assured customers that measures are being taken to safeguard their interests and handle contractual and insurance matters appropriately. The impacted customers were informed of the breach in June and were provided with guidance on necessary steps to take. They were also given a direct line to a Halifax Water representative for any queries or concerns.

The utility disclosed that approximately 55,000 customers have online accounts through the portal. The timeline of events revealed that the vulnerability was first identified in November 2025 and reported to the vendor, Avertra. Although a patch was applied, a subsequent software update in January 2026 rendered the patch ineffective, leading to the re-exposure of the vulnerability.

In further developments, Halifax Water noted that an email alerting them to the vulnerability in February was initially dismissed as spam. However, the issue was later escalated to the cybersecurity team after a follow-up communication in March, prompting the portal to be taken offline for investigation and engagement with a cybersecurity firm.

Enhancements in cybersecurity testing and training have been implemented, along with reinforced processes to promptly address similar third-party reports in the future. While the initial vulnerability has been addressed, additional security gaps were identified, necessitating the portal to remain offline until a secure restoration can be guaranteed. No specific timeline for the portal’s reinstatement has been established, but customers will continue to receive bills via mail until the portal is fully operational.

Latest stories