DIRECT ENERGY, LP
bd_b05c585327449b3c · schema v1 · pii pii-v1
Full breach record for DIRECT ENERGY, LP →2 incidents on fileDirect Energy LP reported a supplemental data breach affecting New Hampshire residents. The incident originated from a ransomware attack on third-party vendor Kitewheel, LLC on November 3, 2020, resulting in the exfiltration of customer data. Affected data includes credit card information (23 residents), bank account information (5 residents), and usernames/passwords (1,163 residents). Direct Energy suspended services with the vendor, reset passwords, notified card networks, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 3, 2020
Begins
Jul 2, 2021
Filed
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- California State AGbd_c3f1bce0188340fd2021-07-12 · +10dCandidate
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Jul 2 (NH), last Jul 12 (CA) — a 10-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.