MalwareRansomwareSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_GOVERNMENTCREDENTIALSMediumContained
DIRECT ENERGY, LP
bd_bd7e340089a059a6 · schema v1 · pii pii-v1
Full breach record for DIRECT ENERGY, LP →Direct Energy LP notified customers of a ransomware attack on a third-party data analytics vendor on November 3, 2020. Unauthorized parties accessed and extracted client files containing customer information, potentially including bank account numbers, credit card data, Social Security numbers, and credentials. The vendor did not pay the ransom. Direct Energy suspended activity with the vendor, notified law enforcement and card networks, and offered two years of identity monitoring.
California clockDiscovered Nov 3, 2020 → Notified Dec 2, 202029d ✓ CA 60-day OK11 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_f994b9ede3225a02Maine State AGfiled 2021-01-08(13d gap)Verified
- bd_8962841e2e4a1fd1Maine State AGfiled 2021-01-06(15d gap)Verified
- bd_15fca67992f8604fMontana State AGfiled 2020-12-02(50d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-537332
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 21, 2021
- Raw hash
- b965cb9791339a7780acad5aa34b5629a410265402f75d764a71a8a4e15d8d3b
Reporting entity
- Name
- DIRECT ENERGY, LPnorm: direct energy
Victim entity
- Name
- DIRECT ENERGY, LPnorm: direct energy
Incident
- Discovered
- Nov 3, 2020
- Materiality determined
- —
- Notification sent
- Dec 2, 2020
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_GOVERNMENTCREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Third party
- via Data analytics vendor
- Initial access
- supply_chain
Compliance
- Time to disclose
- 11 weeks(79 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 29d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 3, 2020→ Notified: Dec 2, 202029d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.