Skip to content

The advisor’s own mailbox started sending phishing. A recipient noticed first.

a wealth management firm · Alberta · December 2018. A financial advisor clicked a phishing link in December 2018. Nothing happened for two months. Then the mailbox began sending phishing in the advisor's name — and the firm learned of it only when a recipient spoke up.

What happened

Identified in the record as Alberta OIPC Decision P2019-ND-099.

2 months between the click and anybody noticing
Missing control

Multi-factor authentication on the mailbox, and anything watching it

First page of Decision P2019-ND-099 Alberta OIPC decision Read the original →

A third-party forensic audit later traced the start to December 2018, when the advisor received a phishing email containing a malicious link, and accessed it.

“No further activity was identified on the account until early February 2019, when the phishing emails were sent.”

When the account came back to life in early February 2019, it sent phishing emails that appeared to come from the advisor to eight Alberta residents. In between, whoever held the credentials had the mailbox itself — content typical of email exchanges between a financial advisor and their client.

“The incident was discovered when an individual who had received the phishing email informed the Organization.”

Nothing the firm ran detected it — not on the day of the click, and not in the two months after. The Commissioner found a real risk of significant harm and required the firm to notify the Alberta residents affected. Thirteen people were affected in all: a small incident by count, on the record here for its timeline.

The rule that applied — in Alberta

Alberta PIPA s.34.1 and s.37.1 — report the breach, then notify everyone affected

“There is a real risk of significant harm to the individuals affected by this incident. Pursuant to section 37.1 of the Personal Information Protection Act (PIPA), the Organization is required to notify those individuals whose personal information was collected in Alberta.”

The document

The part that matters

Two months passed between the advisor clicking the link and anyone realising. Nothing detected it — not the firm, not the software. One of the recipients of the phishing did. That gap is not unusual and it is not free: it is how long somebody else had the correspondence.

An advisor's mailbox holds the client's account numbers, tax information and the whole relationship in writing — the decision says so. That is true in every province. What travels best here is the timeline: the damage was not done on the day of the click.

What your own regulator and insurer require →

The documents

We hold dated copies — ask and we will send you what we read.

DocumentOur copy
Decision P2019-ND-099 Copy held 2026-08-20

Thirteen people were affected, eight of them in Alberta. This is a small incident by count, and it is on this page for the timeline rather than the scale.

Who would notice, and how long would it take?

No cost, no obligation — you keep the findings either way.

Get your free Security Snapshot

Or see what we check for portfolio managers →