Social EngineeringPhishingCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
EVERSOURCE ENERGY
bd_160d257e6f33cfda · schema v1 · pii pii-v1
Full breach record for EVERSOURCE ENERGY →Eversource Energy notified Massachusetts residents of a phishing campaign in April 2026 that compromised customer data via stolen employee credentials. Affected data included names, addresses, SSNs, driver's license numbers, and financial account numbers. Eversource blocked the attackers, engaged external experts, and reported the incident to federal law enforcement. Affected individuals were offered 24 months of IDX identity protection services.
Massachusetts clock✓ MA AG ≤30d4 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_867123e23f9768f0Maine State AGfiled 2026-05-21(20d gap)Verified by operator
- bd_b78e35812ecebc50Vermont State AGfiled 2026-05-21(20d gap)Verified
- bd_c5622f9e262c6888New Hampshire State AGfiled 2026-05-21(20d gap)Verified
- bd_c4e9a718e3076047Indiana State AGfiled 2026-05-27(26d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-828-eversource-energy/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- 23e0695b22450a1ff6b50e836c02495e8cb4277f766fb1fa3834d9d920453894
Reporting entity
- Name
- EVERSOURCE ENERGYnorm: eversource energy
Victim entity
- Name
- EVERSOURCE ENERGYnorm: eversource energy
Incident
- Discovered
- Apr 1, 2026
- Materiality determined
- —
- Notification sent
- May 27, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- reported this incident to federal law enforcement
- Initial access
- phishing_link
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- MA AG ≤30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.