DIRECT ENERGY, LP
bd_bd7e340089a059a6 · schema v1 · pii pii-v1
Full breach record for DIRECT ENERGY, LP →2 incidents on fileDirect Energy LP notified customers of a ransomware attack on a third-party data analytics vendor on November 3, 2020. Unauthorized parties accessed and extracted client files containing customer information, potentially including bank account numbers, credit card data, Social Security numbers, and credentials. The vendor did not pay the ransom. Direct Energy suspended activity with the vendor, notified law enforcement and card networks, and offered two years of identity monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 3, 2020
Begins
Nov 3, 2020
Discovered
Jan 21, 2021
Filed
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- Maine State AGbd_f994b9ede3225a022021-01-08 · +13dVerified
- Maine State AGbd_8962841e2e4a1fd12021-01-06 · +15dVerified
- Illinois State AGbd_18247c0c8da5a2462021-01-01 · +20dVerified
- Montana State AGbd_15fca67992f8604f2020-12-02 · +50dVerified
Show 2 more filings ↓Show fewer ↑up to 386d gap
- New Hampshire State AGbd_195ec47bf66a82462020-12-02 · +50dVerified
- Illinois State AGbd_d00d7ca04529ab442020-01-01 · +386dCandidate
Filing propagation · 7 filings · 5 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Jan 21 (CA) — a 386-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.