EVERSOURCE ENERGY
bd_160d257e6f33cfda · schema v1 · pii pii-v1
Full breach record for EVERSOURCE ENERGY →2 incidents on fileEversource Energy notified customers of a data security incident in April 2026. A cybercriminal phishing campaign resulted in the unauthorized use of two employees' credentials to access files containing customer information, including names, addresses, SSNs, driver's license numbers, and financial account numbers. Eversource blocked the attacker's activities, engaged external experts, and reported the incident to federal law enforcement. Affected individuals are offered 24 months of identity protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 1, 2026
Begins
May 21, 2026
Filed
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- Maine State AGbd_867123e23f9768f02026-05-21Verified by operator
- Vermont State AGbd_b78e35812ecebc502026-05-21Verified
- New Hampshire State AGbd_c5622f9e262c68882026-05-21Verified
- Indiana State AGbd_c4e9a718e30760472026-05-27 · +6dVerified
Filing propagation · 5 filings · 5 states
View merged incident ↗Pattern: first filing May 21 (ME), last May 27 (IN) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.