One phishing click. The client file has not been recovered.
a wealth management firm · Alberta · January 2019. A phishing email went to an Alberta wealth management firm's employees, and one person opened it. The attacker took a client contact file holding names, social insurance numbers, account numbers and assets under management — 767 people in all.
What happened
Identified in the record as Alberta OIPC Decision P2019-ND-074.
Multi-factor authentication on staff mailboxes
On January 23, 2019, a phishing email was sent to the firm's employees. One employee opened it. That was enough: the attacker gained access to the client information in that employee's email contact file.
“name, social insurance number, date of birth, contact information, Organization custody account number and assets under management.”
That is more than identity data. Account numbers and assets under management make the file a target list ranked by assets — and it kept going: the attacker sent phishing emails to a limited number of clients from the employee's contact list. In all, 767 Canadians were affected, 719 of them in Alberta.
The firm engaged two IT firms, one of them a forensic firm, and told the regulator it viewed the risk as relatively low, having uncovered no evidence that the data at issue had been accessed.
“The information has not been recovered.”
The Commissioner found a real risk of significant harm and ordered the firm to notify those affected under Alberta's Personal Information Protection Act.
The rule that applied — in Alberta
Alberta PIPA s.34.1 and s.37.1 — report the breach, then notify everyone affected
“There is a real risk of significant harm to the individuals affected by this incident. The Organization is required to notify those individuals pursuant to section 37.1 of the Personal Information Protection Act (PIPA).”
The part that matters
The firm hired two IT firms, including a forensic one, and still could not say the data had not been taken — only that it had found no evidence. The Commissioner's answer was the shorter one: the information has not been recovered.
The detail to sit with is what was taken: not just identities, but each client's account number and assets under management. That is a target list ranked by wealth, which is worth far more to a fraudster than the identity data alone, and any advisory firm's contact file contains the same thing.
The documents
We hold dated copies — ask and we will send you what we read.
| Document | Our copy |
|---|---|
| Decision P2019-ND-074 | Copy held 2026-08-20 |
| The firm’s own website | Copy held 2026-08-20 |
What would one opened email cost you?
No cost, no obligation — you keep the findings either way.
Get your free Security Snapshot