Skip to content

One phishing click. The client file has not been recovered.

a wealth management firm · Alberta · January 2019. A phishing email went to an Alberta wealth management firm's employees, and one person opened it. The attacker took a client contact file holding names, social insurance numbers, account numbers and assets under management — 767 people in all.

What happened

Identified in the record as Alberta OIPC Decision P2019-ND-074.

767 clients exposed — with their account numbers and assets under management
Missing control

Multi-factor authentication on staff mailboxes

First page of Decision P2019-ND-074 Alberta OIPC decision Read the original →

On January 23, 2019, a phishing email was sent to the firm's employees. One employee opened it. That was enough: the attacker gained access to the client information in that employee's email contact file.

“name, social insurance number, date of birth, contact information, Organization custody account number and assets under management.”

That is more than identity data. Account numbers and assets under management make the file a target list ranked by assets — and it kept going: the attacker sent phishing emails to a limited number of clients from the employee's contact list. In all, 767 Canadians were affected, 719 of them in Alberta.

The firm engaged two IT firms, one of them a forensic firm, and told the regulator it viewed the risk as relatively low, having uncovered no evidence that the data at issue had been accessed.

“The information has not been recovered.”

The Commissioner found a real risk of significant harm and ordered the firm to notify those affected under Alberta's Personal Information Protection Act.

The rule that applied — in Alberta

Alberta PIPA s.34.1 and s.37.1 — report the breach, then notify everyone affected

“There is a real risk of significant harm to the individuals affected by this incident. The Organization is required to notify those individuals pursuant to section 37.1 of the Personal Information Protection Act (PIPA).”

The document

The part that matters

The firm hired two IT firms, including a forensic one, and still could not say the data had not been taken — only that it had found no evidence. The Commissioner's answer was the shorter one: the information has not been recovered.

The detail to sit with is what was taken: not just identities, but each client's account number and assets under management. That is a target list ranked by wealth, which is worth far more to a fraudster than the identity data alone, and any advisory firm's contact file contains the same thing.

What your own regulator and insurer require →

The documents

We hold dated copies — ask and we will send you what we read.

DocumentOur copy
Decision P2019-ND-074 Copy held 2026-08-20
The firm’s own website Copy held 2026-08-20

What would one opened email cost you?

No cost, no obligation — you keep the findings either way.

Get your free Security Snapshot

Or see what we check for portfolio managers →