MalwareRansomwareStolen CredentialsData EncryptedData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)Ransom DemandedFINANCIAL_ACCOUNTCREDENTIALSIDENTITY_BASICLowContained
DIRECT ENERGY, LP
bd_c3f1bce0188340fd · schema v1 · pii pii-v1
Full breach record for DIRECT ENERGY, LP →Direct Energy LP and affiliates experienced a ransomware attack on November 3, 2020, targeting a third-party data analytics vendor. Unauthorized parties accessed and extracted customer files, potentially exposing bank account, credit card, username, password, and SSN data. The vendor did not pay the ransom. Direct Energy suspended the vendor, engaged forensics, notified law enforcement, and offered 24 months of Experian IdentityWorks to affected customers.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-542762
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 12, 2021
- Raw hash
- a893caf5286451e67569349a63524bc66ec4791af017da34360d1840347d4203
Reporting entity
- Name
- DIRECT ENERGY, LPnorm: direct energy
Victim entity
- Name
- DIRECT ENERGY, LPnorm: direct energy
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTCREDENTIALSIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified law enforcement
- Third party
- via Data analytics vendor
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.