MisusePrivilege AbuseCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumActive
New York State Electric & Gas (NYSEG) and Rochester Gas and Electric (RG&E)
bd_1acffb299b140cb9 · schema v1 · pii pii-v1
Full breach record for New York State Electric & Gas (NYSEG) and Rochester Gas and Electric (RG&E) →NYSEG and RG&E disclosed that an employee of a third-party software consulting firm allowed unauthorized access to customer information systems on January 5, 2012. The breach exposed Social Security numbers, dates of birth, and some financial account numbers. The company engaged forensic experts, consulted law enforcement, and offered credit monitoring to affected customers.
California clockDiscovered Jan 1, 2012 → Notified Jan 23, 201222d ✓ CA 60-day OK22 days discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-22146
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 23, 2012
- Raw hash
- d9fe4371246eae9f5c5108a42516950104a92d1a8e7bcf7325744caa25d0ad56
Reporting entity
- Name
- New York State Electric & Gas (NYSEG) and Rochester Gas and Electric (RG&E)norm: new york state electric gas nyseg and rochester gas and electric rg e
Victim entity
- Name
- New York State Electric & Gas (NYSEG) and Rochester Gas and Electric (RG&E)norm: new york state electric gas nyseg and rochester gas and electric rg e
Incident
- Discovered
- Jan 1, 2012
- Materiality determined
- —
- Notification sent
- Jan 23, 2012
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- Partner
- Regulator citations
- Consulted with law enforcement
- Third party
- via independent software development consulting firm
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 22 days(22 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 22d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jan 1, 2012→ Notified: Jan 23, 201222d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.