DisclosureLens
MalwareEnergy & UtilitiesUtilitiesRansomwareSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedFinancial accountCredentialsMediumContained

DIRECT ENERGY, LP

bd_b05c585327449b3c · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Jul 2, 2021

To disclose

Affected

1,191state residents only

Linked

2 filings

Confidence

65%
Full breach record for DIRECT ENERGY, LP2 incidents on file

Direct Energy LP reported a supplemental data breach affecting New Hampshire residents. The incident originated from a ransomware attack on third-party vendor Kitewheel, LLC on November 3, 2020, resulting in the exfiltration of customer data. Affected data includes credit card information (23 residents), bank account information (5 residents), and usernames/passwords (1,163 residents). Direct Energy suspended services with the vendor, reset passwords, notified card networks, and offered credit monitoring.

Incident timeline

Nov 3, 2020

Begins

Jul 2, 2021

Filed

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
New Hampshire State AGJul 2 · first · this page

Pattern: first filing Jul 2 (NH), last Jul 12 (CA) — a 10-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.