Skip to content

Fraud went out from the firm’s own email while the employee was on vacation.

a law firm · Alberta · November 2019. Fraudulent mail went out from an Alberta law firm's own address — the real account of an employee who was away on vacation. Another law firm contacted them to report it. About 400 people had to be notified.

What happened

Identified in the record as Alberta OIPC Breach Notification Decision P2020-ND-033.

≈400 people the firm was ordered to notify, after mail went out in its name
Missing control

Nothing stopping the firm’s own address being used, and no way to notice it

First page of Decision P2020-ND-033 Alberta OIPC decision Read the original →

On November 13, 2019, the firm was contacted by another law firm, which had received a suspicious email that appeared to come from them.

The address was real. The mail was sent from the actual account of one of the firm's employees, who was on vacation at the time. About 60 individuals and companies contacted the firm about the emails.

“The Organization reported that the likelihood that the significant harm will result is “Extremely low. Our office does not typically send emails with links.””

The Commissioner disagreed.

“The unauthorized access did in fact result in fraudulent emails being sent.”

The firm was ordered to notify roughly 400 people whose personal information had been collected in Alberta. Its own conclusion, recorded in the decision, was that IT and training improvements were required. The cost here was never a ransom — it was the firm's clients learning that mail from the firm could not be trusted.

The rule that applied — in Alberta

Alberta PIPA s.34.1 and s.37.1 — report the breach, then notify everyone affected

“There is a real risk of significant harm to the individuals affected by this incident. The Organization is required to notify those individuals whose personal information was collected in Alberta, pursuant to section 37.1 of the Personal Information Protection Act (PIPA).”

The document

The part that matters

The firm's own assessment was that this was extremely low risk. The Commissioner overruled it in a published decision, and about four hundred people got a letter. The cost here was never a ransom — it was the firm's clients learning that mail from the firm could not be trusted, and hearing it from the firm.

This one transfers almost without translation. It is a private law firm, of the size that has no security team, and the failure is the ordinary one: a mailbox somebody else could use, and no mechanism to find out. The statute differs — Alberta PIPA rather than Ontario's PIPEDA — but both make the firm, not its IT provider, responsible for telling everyone affected.

What your own regulator and insurer require →

The documents

We hold dated copies — ask and we will send you what we read.

DocumentOur copy
Decision P2020-ND-033 Copy held 2026-08-20
The decisions index Copy held 2026-08-20

Could mail go out in your firm’s name today?

No cost, no obligation — you keep the findings either way.

Get your free Security Snapshot

Or see what we check for small law firms →