2026 London Hydro — customer portal technical issue; contact and account data accessed
Data compromised
Per company notice: contact information (full name, email, mailing address, phone) and account information (account number, service address, pricing plan, contract start date, meter number/type). Company stated passwords, DOB, government IDs, payment cards, and banking data were not involved. Individual count not published.
Technical writeup
Verified company disclosure — June 20–29, 2026. London Hydro (municipal electricity distributor for London, Ontario; ~170,000 customers per trade press) published a data-security incident notice after detecting unusual account activity on its website portal. Investigation found a technical issue that allowed an unauthorized third party to access and download certain customer data. Categories may include names, emails, mailing addresses, phones, account/billing numbers, service addresses, pricing plans, contract start dates, and meter numbers/types. London Hydro stated financial information, dates of birth, government identification numbers, payment cards, and banking data were not involved, and passwords were not compromised. The utility reported the matter to local law enforcement, engaged external forensics, offered Equifax credit monitoring to eligible affected individuals, and continued customer outreach through late June. No ransomware group publicly claimed the incident at initial reporting. BreachHistory retains recordsAffected 0 pending an attested affected-customer count.
Root cause
Technical issue with customer website portal allowed unauthorized third party to access and download certain customer data; issue identified and corrected same day (company notice)