Skip to content

A staff mailbox was silently forwarding the firm’s mail to criminals.

a real-estate law practice · Alberta · September 2019. For about six weeks, every message into a staff mailbox at an Alberta real-estate law practice was silently forwarded to criminals. The firm found out when a scam email arrived, directing it to deposit funds.

What happened

Identified in the record as Alberta OIPC Decision P2021-ND-027.

6 weeks of incoming mail copied out of the firm before anyone noticed
Missing control

Nothing watching for a mail-forwarding rule on a staff account

First page of Decision P2021-ND-027 Alberta OIPC decision Read the original →

The firm discovered that a staff member's email account had been compromised, and that messages received by the account had been forwarded externally. The account had been exposed for approximately six weeks.

“property address purchased and sold, purchase price for properties, mortgage amounts, mortgage number for the property in question, copy of voided cheque and debit card, and cheque from opposing counsel's client.”

A conveyancing file tells its reader exactly who is about to move a large sum, to whom, and when. The way the firm learned any of this was the fraud itself: it received a scam email, directing it to deposit funds.

“The information involved is available to the public through the land titles registries and we believe that there is very little risk of harm to you as a result of this breach.”

The Commissioner saw it differently — the likelihood of harm was increased because the incident was the result of malicious intent, phishing and an email forwarding rule. The firm notified 181 people in January 2021, of a breach that had begun in September 2019. And the reassurance missed the point: land-titles records are public, but knowing who is about to transfer money, to whom, and when, is not — which is precisely what the scam email tried to exploit.

The rule that applied — in Alberta

Alberta PIPA s.34.1 and s.37.1 — report the breach, then notify everyone affected

“There is a real risk of significant harm to the individuals affected by this incident. The Organization is required to notify those individuals pursuant to section 37.1 of the Personal Information Protection Act (PIPA).”

The document

The part that matters

The firm told 181 people the risk was very little because land titles records are public. That misses what the criminals were actually after: not the records, but the knowledge of who was about to transfer money, to whom, and when. Which is precisely what the scam email then tried to exploit.

Real-estate files are the ones criminals want, because they tell you exactly who is about to move a large sum and to whom. The statute here is Alberta's, but any firm that handles a closing has this exposure, and the mechanism — a forwarding rule nobody looks for — is identical everywhere.

What your own regulator and insurer require →

The documents

We hold dated copies — ask and we will send you what we read.

DocumentOur copy
Decision P2021-ND-027 Copy held 2026-08-20

The decision does not label the organisation, but it records a “cheque from opposing counsel's client” alongside a file of property purchases, sales and mortgage numbers — an organisation with opposing counsel is counsel. The breach ran from September 2019; affected individuals were notified in January 2021.

Would you know if your mail were being forwarded?

No cost, no obligation — you keep the findings either way.

Get your free Security Snapshot

Or see what we check for small law firms →