DisclosureLens
AccidentalEnergy & UtilitiesUtilitiesMisconfigurationCustomer Data InvolvedIdentity (basic)Government IDMediumContained

NSTAR ELECTRIC COMPANY

bd_6b5cd1378c070015 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 16, 2021

Filed

Apr 16, 2021

To disclose

4 weeks

Affected

128state residents only

Linked

2 filings

Confidence

67%
Full breach record for NSTAR ELECTRIC COMPANY

NSTAR Electric Company (dba Eversource Energy) reported a security incident to the New Hampshire Attorney General on April 16, 2021. On March 16, 2021, the company discovered an Azure cloud storage folder was misconfigured, allowing potential public access. The folder contained personal information (names, addresses, SSNs, utility account info) for 128 New Hampshire residents who had Massachusetts service addresses. No financial account data was involved. The company restricted access immediately, investigated, and found no evidence of unauthorized access or misuse. Notices were sent to affected residents, who were offered 24 months of credit monitoring.

Incident timeline

discovery → filing · 4 weeks / 31 days

Mar 16, 2021

Discovered

Apr 16, 2021

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Massachusetts State AGApr 16 · first
New Hampshire State AGApr 16 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.