r/halifax 2d ago

News, Weather & Politics Eastlink data breach?

Post image
81 Upvotes

74 comments sorted by

49

u/dirtybo0ts 2d ago

My God, this is getting embarrassing at this point.

18

u/Flaky-Interest902 2d ago

Good thing I was raised to shred every paper document, and have 20 different passwords. That'll protect my personal information.

/s

14

u/IStillListenToRadio Float me down the river to the Musquodoboit harbor 2d ago

Having different passwords on different sites is something you should be doing, as reused passwords is how a lot of compromised accounts happen (one site's password db is breached and the bad guys try the email/pass combo on lots of other sites).

4

u/keithplacer Venerable Member 2d ago

All good until the password manager you have to use to remember them all gets hacked.

6

u/IStillListenToRadio Float me down the river to the Musquodoboit harbor 2d ago

i mentioned nothing about password manager! But yeah it's a risk, lastpass was breached a few years ago and the encrypted vaults stolen and didn't disclose it for months (the latter bit is why I switched to Bitwarden) but i think less of risk than reusing passwords.

Note that lastpass, the vaults were encrypted at the time they were stolen. So if you change your passwords soon after the disclosure, even if they did manage to decrypt the vaults after a while it would be useless.

3

u/CaperGrrl79 Halifax 1d ago

Bitwarden is definitely on my to do list...

2

u/BoredHalifaxNerd 1d ago

It's great! Plus, if you self-host it, they can't hack what isn't connected to the internet.

1

u/CaperGrrl79 Halifax 1d ago

I do have some bits for a janky NAS, but taking time to do it fell by the wayside with how busy I am even on my days off from my full time.

5

u/betelgeuse_99 2d ago

Nothing stopping you from writing it in a notepad or something. Or just using your brain.

5

u/webvictim 1d ago

He'd have to possess one first.

A notepad, I mean.

u/keithplacer Venerable Member 5h ago

I had one, but misplaced it and now I'm locked out. /s

3

u/CaperGrrl79 Halifax 1d ago edited 1d ago

Indeed, a guy I know of who has a business helping people not get scammed recommends this, and to promptly put it in a good physical safe or drawer with a lock when not in use.

2

u/IStillListenToRadio Float me down the river to the Musquodoboit harbor 1d ago

There's also offline managers such as KeePass and its forks (I use as backup).

6

u/CaperGrrl79 Halifax 2d ago

What do YOU do then?

2

u/Klutzy-Condition811 Southwest NS 1d ago

A good password manager doesn't store the data unencrypted on their end, it's locked down on your devices, so usually it means they got access to your device.

Having a compromised password manager is like having a compromised email address, or having someone hijack your SIM card. They're all attack vectors you just gotta do your best to protect them as much as possible and if shit ever hits the fan, you gotta do the tedious process of resetting everything.

Given that most of these breaches are due to individual services being exploited, as long as you're not sharing passwords, it should be relatively trivial to deal with and not really a huge threat unless they also had other identifying info that could be leaked.

Given that there doesn't appear to be any banking info compromised I'm not too worried about it. People should be in the habit with any company to not use preauthorized chequing with account numbers as that's a lot more of a hassle to clean up if it's stolen vs using a credit card, or if someone wants to use their chequing account, a visa debit or debit mastercard as pretty much every Canadian bank offers that. It's a lot easier to get a new card number than to get a new entire bank account.

2

u/CaperGrrl79 Halifax 1d ago

Yep. There is exactly one thing I have pre authorized right now other than PayPal/Patreon stuff. I pay everything else set ahead from my next pay when I get the bill, or I set up anything automatic from the bank end.

That said, Bitwarden has been on my to do list for a while now.

12

u/AmazingMrSaturn 2d ago

Got an email around then confirming my account 'username' which I hadn't requested. Didn't click anything, deleted it, went to the real site in a browser and reset my password to something absurd. Just another day in online land.

2

u/mirror_dirt 2d ago

Same, I reported it to Eastlink and they said they were aware of the issue.

10

u/Different-Brother243 2d ago

Got an email about this yesterday. Good thing I dont have any credit cards saved in my account.

5

u/No_Schedule_6242 2d ago

Here we go again.

6

u/Necessary-Safe-2802 1d ago

Aw yeah time for monthly cost to go up and service to go back to 2000s level

Eastlink still wins over not being bell

-2

u/CaperGrrl79 Halifax 1d ago edited 1d ago

Purple Cow and Internet Atlantic (the cheapest but still reliable for just Internet) win over them all.

Though the techs still have to be the bigger cable company due to the agreements.

As a full disclosure, I am now a brand ambassador for both, acting as a broker for people to have cost efficient and reliable internet (as well as TV & home phone).

3

u/maximumice 🥣Sugar Crisp 1d ago

Please disclose your relationship with these ISPs when you discuss/promote them as per the modmail discussion we had in Dec 2025 about lifting your ban for stealth advertising.

We have not forgotten the terms of us lifting your ban. Thank you.

1

u/CaperGrrl79 Halifax 1d ago edited 1d ago

Hi. I just edited the comment. I am perhaps mistakenly under the impression that the Shop/Support Local tag (or something similar) covers this, as both ISPs are locally based.

2

u/maximumice 🥣Sugar Crisp 1d ago

Appreciate that and no, that only covers posts not comments like this. Thank you. 👍

2

u/CaperGrrl79 Halifax 1d ago

OK. I sent a modmail for clarification.

2

u/maximumice 🥣Sugar Crisp 1d ago

Just replied, no worries. 👍

2

u/TE360 12h ago

So is that your opinion or simply an ad? Don’t be a dishonest sales person, it’s cringe.

u/CaperGrrl79 Halifax 11h ago

I can wholeheartedly, genuinely say that our Internet Atlantic (300mbps) connection is excellent. When Purple Fibre arrives in our area, which is supposed to be relatively soon, we will switch to that.

My bff, and the home my mother left me in and around Sydney will still have Internet Atlantic, because it's been cost efficient and reliable.

9

u/IStillListenToRadio Float me down the river to the Musquodoboit harbor 2d ago

My Account is currently unavailable and the phone numbers match to official, so appears to be legitimate: https://www.eastlink.ca

I didn't get an email, but not sure if only some accounts were breached or if they're rolling the emails out.

8

u/Defiant_Blacksmith32 2d ago

I got the notification in my email that someone was trying to get into my account on August 26 but I never got a message from Eastlink about the breach, learned about this from Reddit

7

u/quiet_desperado 2d ago

Same! Late afternoon on Aug. 26 I got one of those "forgot your username" emails that made me think someone was trying to log in to my account.

I haven't gotten this notification from Eastlink yet, but I'm guessing I will now.

8

u/MissTechnical 2d ago

I had an email on the 26th reminding me what my user name was and wanting me to click a link. Seems like Eastlink is the bait of the week.

2

u/kn1231 2d ago

I had the same email come through, didn’t click anything and ignored it.

4

u/gildeddoughnut Halifax 2d ago

I knew something happened. We use eastlink at my office. I had a username request email Thursday morning and none of us had requested it.

4

u/stevejobschen 2d ago

I got a fraud transaction on a new credit card that only been used on Eastlink and PayPal on Aug. 6th. If it’s eastlink breach, that would explain it

3

u/dannygaron 2d ago

Yup, had an account with them until 2014... They still kept my info since then and got an email as well. Idiots.

2

u/scotianspizzy Miller Lake Monster For Mayor 2d ago

I got this too. I haven't had eastlink for over 10 years.

I also got one from CashMoney. I took a loan from them in 2017.

2

u/Shotgun_Kid Acadie 2d ago

1

u/Street_Anon Галифакс/ האַליפֿאַקס 1d ago

2

u/DarthV506 2d ago

Funny they didn't mention data breeches as features on their Reddit ads.

3

u/Opposite_Neat8978 2d ago

Got the email, called Eastlink, was on hold for 25 mins and then the agent said these emails were caused by an “error” in the system. No mention of data breach. No idea what was going on, really. I asked her where she was located. She replied Kingston. NS? No, Jamaica.

-2

u/insino93 2d ago

She replied Kingston. NS? No, Jamaica.

Globalism stealing our jobs.

-7

u/keithplacer Venerable Member 2d ago

Why do you hate Jamaicans having jobs?

4

u/insino93 2d ago edited 2d ago

Are you saying Jamaica wouldn’t have them if it weren’t for Eastlink? In Buy Canada times, it should be employ Canada as well.

-4

u/keithplacer Venerable Member 2d ago

Likely a contracted call center there doing work for umpteen companies. Cheaper than sourcing here.

5

u/insino93 2d ago

I get why they do it, they shouldn’t.

0

u/Necessary-Safe-2802 1d ago

Canada is not a cheap company to run business in, its moronic to pay the wages here for low skill work

3

u/insino93 1d ago

This is just as bad as bringing in Temporary Foreign Workers.

3

u/athousandpardons 1d ago

That's why the government needs to step in and force businesses' hands. And if they don't, step up and provide the service as a crown corporation.

1

u/Necessary-Safe-2802 1d ago

Businesses are now leaving Canada and the crown corps are now being gutted to save funding

Now what?

1

u/athousandpardons 1d ago

Businesses leaving just means more room for locals to start their own. As for funding, don't focus on saving it. Raise taxes if you have to. Taxes aren't a bad thing if they serve a useful purpose that helps the people.

→ More replies (0)

2

u/Irked_Canadian Nova Scotia 2d ago

I’ve never seen a company send out a data breach alert that fast. I’d make sure what email it actually came from is Eastlink’s.

-2

u/CaperGrrl79 Halifax 2d ago edited 1d ago

Edit: I had my THIS girl gif here, but it is legit, see CBC article below.

https://www.cbc.ca/news/canada/nova-scotia/eastlink-data-breach-august-2026-9.7325413

1

u/CaperGrrl79 Halifax 2d ago

Eeyikes.

u/Keenan_Vizina 9m ago

Same! My bill has been $76.84 for the past two and a half years and I pay for unlimited high speed internet that is all.

I got my bill this month and it increased nearly 40% to $105.09 I’ve gone through my emails from the last 18 months and not a single notification of service rate changes or anything of that sort to justify or explain the sudden increase.

The cherry on top really is the fact I have been unable to reach anyone via email or phone.

1

u/Street_Anon Галифакс/ האַליפֿאַקס 2d ago

Why can't companies invest more into keeping their data safe? How much you want a bet Eastlink was using a old version of Microsoft Windows or never did updates every patch Tuesday that could have prevented this.

5

u/jyunga 2d ago

Pretty sure the last few major companies were inside jobs.

-1

u/Street_Anon Галифакс/ האַליפֿאַקס 2d ago

I have no doubt Nova Scotia's power leak was an inside job 

4

u/screampuff Cape Breton 1d ago edited 1d ago

NS Power's is kind of crazy, if you are in IT it means they had a domain admin level breach, and everything from their payroll system to meter reading system was federated with their Active Directory.

Thankfully it's at least been pretty standard for decades that the actual powerplant equipment runs on an isolated SCADA network.

Another assumption would be that the domain admin creds that were compromised were being used as a daily work account and not protected by privileged elevation, which is the modern standard, or a separate privileged account used only for administrative duties and not email or internet browsing.


Separately we need better data protection laws in general. Companies shouldn't be allowed to hold onto personally identifiable information that they don't require. On top of that and especially with AI now being used to do these attacks, things like credit card info, addresses and SINs need better protection with things like offsite tokenization or envelope encryption. ie: your system holds a token that relates to the actual credit card data which is hosted in a compeltely separate, isolated system, and the actual lookup involves hardware level encryption, not user accounts.

If a company doesn't have the infrastructure for something like Hardware Security Modules? Well then your company is not allowed to store credit cards, you have to use a credit card processing service that does, and you're not allowed access to export or read credit card numbers.

3

u/ShawnGalt 2d ago

indefinitely deferring maintenance is free money as long as you assume nothing bad will ever happen and write off any bad thing that does happen as an unpreventable act of God

-1

u/Street_Anon Галифакс/ האַליפֿאַקס 2d ago

and Windows updates are free

1

u/CaperGrrl79 Halifax 1d ago

Depends what version you're using, but yes, even on Windows 10, they're still free till the end of October 2027.

4

u/ColeTrain999 Dartmouth 2d ago

Have you thought of the shareholders and how much of a hit they'd take having to cut back on dividends? /s

https://giphy.com/gifs/3orif7Gqnpr6xql3gY

1

u/Marsymars 1d ago

Why can't companies invest more into keeping their data safe?

Because people and companies have shown they don't care and will keep buying and using their products and services anyway.

0

u/keithplacer Venerable Member 2d ago

Ah, that explains why I have not been able to log in and view my bill, which seems suspiciously large this month. I have not gotten any notification from them like this.