The attacker hid every incoming message in Deleted Items. Nobody noticed.
a firm holding its clients’ banking details · Alberta · November 2015. An employee is believed to have clicked a phishing email in November 2015. The attacker set a rule sending every incoming message to Deleted Items and sat unnoticed for seven months — in the mailbox of a firm holding its clients' banking details.
What happened
Identified in the record as Alberta OIPC Decision P2019-ND-063.
Anything watching the mailbox, including the rule the attacker left behind
The firm believes it started with a click on a phishing email, on November 20, 2015.
“In addition a rule was set up in the Outlook account, which redirected all incoming emails to the deleted items folder.”
That rule bought the silence. With every incoming message diverted, whatever anyone sent back never reached the person who owned the mailbox. The firm suspects the intrusion went unnoticed for seven months.
The firm held its clients' names, addresses, telephone numbers, email addresses, dates of birth, social insurance numbers and banking information.
“The incident was discovered when the employee received a telephone call from one of the recipients of the phishing email sent from the compromised account.”
The firm's own view was that no significant harm would result. The Commissioner's view was that the risk was already real: phishing had gone out from the firm's own mailbox — and it was required to notify everyone affected under Alberta's Personal Information Protection Act. The decision never reports how many people that was, and never says what the firm does; the record supports only whose data it held.
The rule that applied — in Alberta
Alberta PIPA s.34.1 and s.37.1 — report the breach, then notify everyone affected
“There is a real risk of significant harm to the individuals affected by this incident. The Organization is required to notify those individuals pursuant to section 37.1 of the Personal Information Protection Act (PIPA).”
The part that matters
The firm's own view was that no significant harm would result. The Commissioner's view was that the risk was already real — phishing had gone out from the firm's own mailbox — and that seven months of silence was not evidence of safety.
The attacker did not merely get in; they made sure the person who owned the mailbox would not see the replies. That is the part worth internalising: the quiet period is not luck, it is engineered, and it ends when a client notices rather than when you do.
The documents
We hold dated copies — ask and we will send you what we read.
| Document | Our copy |
|---|---|
| Decision P2019-ND-063 | Copy held 2026-08-20 |
The organisation never reported how many people were affected, and the decision does not state its line of business — so we describe it only by what the record supports.
How long would seven months cost you?
No cost, no obligation — you keep the findings either way.
Get your free Security Snapshot