HackingUtilitiesVulnerability ExploitData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICHighContained
EVERSOURCE ENERGY
bd_867123e23f9768f0 · schema v1 · pii pii-v1
Full breach record for EVERSOURCE ENERGY →Eversource Energy reported an external system breach (hacking) occurring on April 14, 2026, discovered on April 27, 2026. The incident affected 3,049 individuals, including 1 Maine resident. The breach involved the acquisition of personal identifiers, including government IDs. Eversource provided written notification and offered 24 months of identity protection services through IDX.
Maine clockDiscovered Apr 27, 2026 → Filed with AG May 21, 202624d ✓ ME AG ≤30d24 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_b78e35812ecebc50Vermont State AGfiled 2026-05-21Verified
- bd_c5622f9e262c6888New Hampshire State AGfiled 2026-05-21Verified
- bd_c4e9a718e3076047Indiana State AGfiled 2026-05-27(6d gap)Verified
- bd_160d257e6f33cfdaMassachusetts State AGfiled 2026-05-01(20d gap)Candidate
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/5a095898-f480-4579-8193-f1f4fc07a451.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 21, 2026
- Raw hash
- 7866c62ab619d2df7fe6430eb8e7d5748e3655bbb6075e89935b6f6a68c93a09
Reporting entity
- Name
- EVERSOURCE ENERGYnorm: eversource energy
Victim entity
- Name
- EVERSOURCE ENERGYnorm: eversource energy
Incident
- Discovered
- Apr 27, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 3,049
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Filed data breach notice with Maine Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- ME AG ≤30d · 24d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Apr 27, 2026→ Filed with AG: May 21, 202624d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.