Halifax Water provides update on Customer Connect portal privacy incident

Sixteen customer accounts accessed; affected customers notified directly; portal remains offline
Published:
Updated: 9:59 AM | August 13, 2026

An independent forensic investigation by third-party cybersecurity experts has concluded its review of Halifax Water’s March 2026 Customer Connect portal privacy incident, confirming limited information linked to 16 customer accounts was accessed. The affected customers have been notified, and the portal remains offline until Halifax Water is satisfied that service can be restored securely.

This update explains what happened, what information was involved, what the investigation found about customer risk, and the steps customers can take to protect themselves.

“Our review found that a vulnerability in a third-party platform allowed unauthorized access to certain customer information. We are taking the time needed to understand the circumstances fully, protect customers’ interests, and address the related contractual and insurance matters appropriately,” said Kenda MacKenzie, CEO, Halifax Water. “We are sorry for the concern this has caused. We have notified the 16 affected customers directly, expanded our cybersecurity testing, strengthened escalation processes for security-related incident reports, and will keep the portal offline until it can be restored securely.”

What happened 
The privacy incident involved a vulnerability in the third-party platform that powers the Customer Connect portal, which allowed an external party to access customer information from the portal database. This was not a cyber security attack on Halifax Water’s systems, nor did it involve the systems that control water and wastewater services.

Halifax Water identified a vulnerability in the portal through its own proactive security monitoring in November 2025 and reported it to the portal vendor, Avertra. Halifax Water received confirmation that the security patch had been applied. In January 2026, a vendor software update rendered the earlier patch ineffective and re-exposed the vulnerability.

What information was involved 
An independent forensic investigation has confirmed that an unauthorized external party accessed information linked to 16 customer accounts. There is no evidence that any customer accounts were directly accessed or any other information was involved.

Approximately 55,000 customers hold Customer Connect portal accounts.

For those 16 accounts, the categories of information accessed varied but were limited to:

  • Full name 
  • Email address 
  • Service or home address; account ID, customer ID and user ID 
  • Security questions and answers  

No financial information was accessible or exposed.  

Halifax Water’s payment systems and operational systems were not involved in this incident. The affected portal database did not include credit card or banking information, and the systems that control water and wastewater services were not affected.

Who was affected, and how they were notified 
In June 2026, Halifax Water notified the 16 customers whose accounts were accessed by registered mail. The impacted customers were provided with information on what occurred, what it means, and what steps to take, and were given a direct line to a Halifax Water representative for questions or concerns.

Halifax Water notified the appropriate oversight bodies as part of its response to the incident.

A gap in our internal process 
Halifax Water also wants to be transparent about a shortfall in an internal process. In February 2026, an unknown third party emailed Halifax Water’s Customer Service team about the vulnerability, and the initial email was dismissed as spam. In March 2026, the same party followed up with Customer Care, and the follow-up email was reported to the Help Desk. The ticket was escalated to the cyber security team and triggered the full response described above. Cyber security awareness training has increased across the organization, and internal ticket routing and escalation processes have been updated to immediately flag and escalate these types of security-related reports from outside the organization.

What happens next 
The Customer Connect portal remains offline. The fix for the original vulnerability has been independently tested and confirmed effective, but further security testing has identified additional vulnerabilities. That work is ongoing, and the portal will remain offline until Halifax Water is satisfied that service can be restored securely. No restoration date has been set.

Halifax Water will communicate a timeline once one is confirmed. In the meantime, bills are being sent by mail, and Halifax Water apologizes for the inconvenience.

Halifax Water is also reviewing its vendor contract, security standards, oversight protocols, and any related insurance or contractual matters to ensure customers’ interests are protected. Halifax Water will provide further public updates on the structural changes made as a result of this incident.

Timeline 
Halifax Water is publishing the following timeline in the interest of transparency.

 

Period  What happened 
November 2025  Halifax Water identifies a vulnerability in the portal through its own proactive security monitoring and reports it to the vendor. A patch is applied and confirmed to Halifax Water’s satisfaction at that time. 
January 2026   A vendor software update rendered the earlier patch ineffective and re-exposed the vulnerability.  
February 2026  Customer Care received an initial email from an unknown third party regarding the vulnerability. The initial email was dismissed as spam. 
March 2026  The third party followed up with Customer Care, and the follow-up email was reported to the Help Desk. IT reviewed the ticket and escalated it to the cyber security team, which began the response. The portal was taken offline, an independent cybersecurity firm was engaged, and the relevant authorities were notified. 
April 2026  The forensic investigation is substantially complete. The vendor’s fix is independently tested and verified. Additional security testing begins. 
May 2026  The extent of the incident is confirmed: information linked to 16 customer accounts were accessed. 
June 2026  The 16 affected customers are notified directly by registered mail, with a phone number provided for questions or concerns. 
July 2026  Further security testing identifies additional vulnerabilities. The portal remains offline and no restoration date has been set. 


What customers should do

Even though there is no evidence that customer accounts were accessed directly or that other information is involved, Halifax Water encourages all Customer Connect portal users to take the following precautions: 

  • Use a unique password for every service and change any password you have reused. 
  • Turn on multi-factor authentication wherever it is available. 
  • Change your security questions and answers on other services if you use the same ones you used on the Halifax Water portal. 
  • Be alert to phishing. Halifax Water will not call, email or text you to ask for personal information about this incident. 
  • Watch your accounts for unusual activity and report anything suspicious to your financial institution.

Halifax Water remains committed to protecting customer information, strengthening the systems and processes that support customer service, and communicating openly as this work continues. 
 

Halifax Water