DisclosureLens
HackingFinancial ServicesFinanceStolen CredentialsCustomer Data InvolvedPIIIdentity (basic)Financial accountLowContained

Energy Federation, Inc.

bd_402e823eac52e23d · schema v1 · pii pii-v1

Severity

Low

Discovered

Jul 12, 2011

Filed

Jul 27, 2011

To disclose

15 days

Affected

20state residents only

Confidence

66%

Energy Federation, Inc. notified NH AG of a potential security breach involving malicious files placed on its web server between July 7-10, 2011. The files allowed remote collection of customer data (names, contact info, credit card numbers) for orders placed July 7-12, 2011. 20 NH residents potentially affected. No evidence of actual misuse found. Company removed files, reset passwords, engaged forensic experts, notified law enforcement, and provided 1 year of credit monitoring.

Incident timeline

undetected · 5 days
discovery → filing · 15 days

Jul 7, 2011

Begins

Jul 12, 2011

Discovered

Jul 27, 2011

Filed

vs. sector median

6 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed20 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.