The advisor’s own mailbox started sending phishing. A recipient noticed first.
a wealth management firm · Alberta · December 2018. A financial advisor clicked a phishing link in December 2018. Nothing happened for two months. Then the mailbox began sending phishing in the advisor's name — and the firm learned of it only when a recipient spoke up.
What happened
Identified in the record as Alberta OIPC Decision P2019-ND-099.
Multi-factor authentication on the mailbox, and anything watching it
A third-party forensic audit later traced the start to December 2018, when the advisor received a phishing email containing a malicious link, and accessed it.
“No further activity was identified on the account until early February 2019, when the phishing emails were sent.”
When the account came back to life in early February 2019, it sent phishing emails that appeared to come from the advisor to eight Alberta residents. In between, whoever held the credentials had the mailbox itself — content typical of email exchanges between a financial advisor and their client.
“The incident was discovered when an individual who had received the phishing email informed the Organization.”
Nothing the firm ran detected it — not on the day of the click, and not in the two months after. The Commissioner found a real risk of significant harm and required the firm to notify the Alberta residents affected. Thirteen people were affected in all: a small incident by count, on the record here for its timeline.
The rule that applied — in Alberta
Alberta PIPA s.34.1 and s.37.1 — report the breach, then notify everyone affected
“There is a real risk of significant harm to the individuals affected by this incident. Pursuant to section 37.1 of the Personal Information Protection Act (PIPA), the Organization is required to notify those individuals whose personal information was collected in Alberta.”
The part that matters
Two months passed between the advisor clicking the link and anyone realising. Nothing detected it — not the firm, not the software. One of the recipients of the phishing did. That gap is not unusual and it is not free: it is how long somebody else had the correspondence.
An advisor's mailbox holds the client's account numbers, tax information and the whole relationship in writing — the decision says so. That is true in every province. What travels best here is the timeline: the damage was not done on the day of the click.
The documents
We hold dated copies — ask and we will send you what we read.
| Document | Our copy |
|---|---|
| Decision P2019-ND-099 | Copy held 2026-08-20 |
Thirteen people were affected, eight of them in Alberta. This is a small incident by count, and it is on this page for the timeline rather than the scale.
Who would notice, and how long would it take?
No cost, no obligation — you keep the findings either way.
Get your free Security Snapshot