London Hydro Discloses Customer Data Breach: What Was Reportedly Exposed & What To Do
London Hydro disclosed a data breach on June 23, 2026 affecting approximately 170,000 customers. Customers should check whether their information was exposed and take appropriate protective steps.
Inside the incident
London Hydro stated that hackers stole the listed categories of customer data. The utility reported the matter publicly on June 23, 2026, and indicated that the breach potentially affects its full customer base of approximately 170,000. No further details on the date or method of unauthorized access have been released, and the investigation is described as ongoing.
How a breach like this happens
Incidents involving the theft of customer contact and account records often begin with unauthorized entry through remote access points, misconfigured systems, or compromised credentials. Once inside, attackers locate and copy structured data from customer databases before exfiltrating it. Such events can remain undetected for weeks or months until unusual activity or external notification prompts review.
About London Hydro
London Hydro is a Canadian electricity utility serving customers in the London, Ontario region. Organizations of this type maintain records necessary to deliver service, issue bills, and manage accounts. Because these records contain both personal identifiers and service-specific details, a breach can affect a large portion of the local population that relies on the utility for essential power supply.
The information in question
The utility has confirmed exposure of names, addresses, email addresses, phone numbers, and account information including billing numbers, service addresses, pricing plans, and meter details. It has also stated that financial data, Social Security numbers, and payment card information were not involved. The precise scope of records accessed and any additional fields remain unconfirmed pending further investigation.
The real-world impact
Customers may experience an increase in phishing attempts or unwanted contact that references their utility account. Account numbers and meter details could be used to craft more convincing impersonation attempts, though the absence of payment information limits direct financial fraud vectors. For the organization, the incident requires notification, investigation, and potential changes to security controls that protect customer systems.
If your data was in this claimed breach
Review any communications from London Hydro for instructions on monitoring accounts or resetting credentials. Treat unsolicited messages referencing your utility service with caution and verify contacts through official channels. Consider enabling available account alerts and using unique passwords for utility-related logins.
- Monitor email and phone for unexpected activity tied to your account.
- Confirm billing statements directly through the utility’s verified portal.
- Run a free exposure scan of your email address against known breach data to check for additional appearances.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
CISA Adds One Vulnerability to KEV CatalogCISA Adds Two Vulnerabilities to KEV CatalogLatvian State Forestry Company LVM Hit by RansomwareVirginia Museum of History & Culture Breached by TheGentlemenLatest breaches
Read GalaxyWarden’s full analysis of the London Hydro Discloses Customer Data Breach →
Based on public reporting
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.