DIRECT ENERGY, LP
bd_c3f1bce0188340fd · schema v1 · pii pii-v1
Full breach record for DIRECT ENERGY, LP →2 incidents on fileDirect Energy LP and affiliates experienced a ransomware attack on November 3, 2020, targeting a third-party data analytics vendor. Unauthorized parties accessed and extracted customer files, potentially exposing bank account, credit card, username, password, and SSN data. The vendor did not pay the ransom. Direct Energy suspended the vendor, engaged forensics, notified law enforcement, and offered 24 months of Experian IdentityWorks to affected customers.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 3, 2020
Begins
Jul 12, 2021
Filed
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- New Hampshire State AGbd_b05c585327449b3c2021-07-02 · +10dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Jul 2 (NH), last Jul 12 (CA) — a 10-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.