CSIDB logo
Incident

Eastlink

Incident posture

Attack window
Aug 2026
Location
Canada
Status
Unknown
CIA posture
Available to members
Updated
2026-08-31 08:11

Linked entities

Victim
Eastlink
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A Canadian telecommunications provider operating across seven provinces and Bermuda notified customers of a potential data breach affecting accounts that may have been compromised between late Wednesday and early Thursday morning. The company sent initial email notifications to affected customers before the weekend and stated that exposed information may include customer names, contact details, account numbers, and PINs, though it does not believe credit card or banking information was involved. After learning of the breach, the company shut down affected platforms on its website and mobile app and committed to using additional communication channels, including letters and further web updates, to reach potentially impacted individuals, including those with historical accounts. The exact number of affected customers remains unclear, and the company indicated it is still gathering details about the incident.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Telecommunications provider Eastlink, which operates across seven Canadian provinces and Bermuda, notified certain customers in late August 2026 of a potential data breach affecting their accounts. The company sent an initial email to some affected customers on a Friday just before 5 p.m. Atlantic time, warning them that their information may have been compromised between late Wednesday and early Thursday morning of the preceding week. According to Eastlink's notification, the exposed information may have included customer names, contact details, account numbers, and PINs. The company stated that it did not believe credit card or banking information was exposed in the incident.

Eastlink reported that, upon learning of the incident on Wednesday, it promptly shut down affected platforms on its website and mobile app. The company continued to notify customers beyond the initial email, with spokesperson Jill Laing indicating in communications with CBC News that Eastlink was gathering further details. Laing noted that no one at the company could speak publicly about the matter until Monday following the breach notification. She added that Eastlink would be "using all reasonable channels of notification in the coming days and beyond including email updates, letters, additional web updates and other channels to ensure all potentially affected customers receive the most up-to-date information." Eastlink also apologized to customers in its initial email regarding the incident.

The exact scope of the breach remained unclear, as the number of affected individuals had not been publicly disclosed. Among those notified was Caitlyn Horne of Halifax, who had ended her internet service with Eastlink in 2023, indicating that the breach notification reached beyond current customers to include individuals with historical accounts. Horne expressed concern about the breach, stating her initial reaction was "Oh no, not again," citing the frequency of data breaches more broadly. She also questioned what information might have been accessed, remarking, "Oh God, what do they have their hands on? Like, what don't I know right now?" Horne indicated she hoped Eastlink would offer greater transparency about the situation and provide credit monitoring services to affected customers. As of the article's publication date of August 29, 2026, Eastlink was continuing its investigation and notification efforts.

Sources

Sources available to members: 1 source.

CSIDB