On June 20, 2026, municipal electricity distributor London Hydro told customers in London, Ontario that a flaw in its website portal let an unauthorized party download contact and account data.
This is not a grid-takeover story. Power kept flowing. What leaked is the kind of customer file that makes fake-bill phishing and account-takeover calls much easier.
What happened
Per London Hydro’s incident page and coverage by SecurityWeek, the utility spotted unusual portal activity, opened an investigation the same day, and found a technical issue that allowed certain customer records to be accessed and downloaded. It fixed the issue, notified local law enforcement, and brought in external forensics.
SecurityWeek notes London Hydro serves roughly 170,000 residential, commercial, and industrial customers. The company has not published how many of those accounts were in the download set.
What data was exposed
London Hydro says the accessed information may include:
- Contact details — full name, email, mailing address, phone number
- Account details — London Hydro account number, service address, pricing plan, contract start date, meter number, and meter type
Those fields are enough to craft convincing “your bill is overdue / update payment” messages that look local.
What was not exposed
The utility is explicit about the negatives: no passwords involved (so no forced reset), and no access to dates of birth, government ID numbers, payment card details, or banking information. That lowers classic identity-theft risk versus an SSN dump—but it does not stop social engineering against the utility relationship itself.
Who is at risk
London Hydro customers whose notice letters or emails confirm inclusion. Neighbors who did not get a letter should still treat unexpected utility SMS or email as hostile until verified through the official site or phone number on a past bill—not a link in the message.
Action items
- Read any London Hydro notice carefully and activate Equifax monitoring only with the code in that notice—not from a cold call.
- Ignore unexpected payment-change or “re-verify meter” messages; call 519-661-5503 or use contacts on londonhydro.com.
- Report suspicious utility phishing to the Canadian Anti-Fraud Centre and [email protected].
- Keep using a unique password for MyLondonHydro even though this incident did not steal passwords.
Canonical record
London Hydro June 2026 portal breach. Sources: company notice, SecurityWeek.