HackingFinancial ServicesFinanceCustomer Data InvolvedPIILow
FIVE STATES ENERGY COMPANY, L.L.C.
bd_fdec22ccffee3a4f · schema v1 · pii pii-v1
Full breach record for FIVE STATES ENERGY COMPANY, L.L.C. →Five States Energy Company, LLC (Dallas, TX) reported an external system breach (hacking) that occurred and was discovered on 02/12/2026. A total of 2,251 individuals were affected, including 9 Maine residents. Written notification was sent to affected consumers on 03/26/2026. Identity theft protection services were offered through CyberScout, a TransUnion company.
Maine clockDiscovered Feb 12, 2026 → Filed with AG Apr 2, 202649d ⏱ ME AG >30d7 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
This filing is one of 5 about the same incident.View merged incident
A leak claim by dragonforce about this victim predates this filing by 49 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_10e7db3f7644f406Leak Sitedragonforcefiled 2026-02-19(41d gap)Verified
- bd_e39e6d2fa52a6db3Leak Sitedragonforcefiled 2026-02-12(49d gap)Verified by operator
Regulatory filings (2) · sorted by filing gap
- bd_f089861523f7f475Vermont State AGfiled 2026-04-02Verified by operator
- bd_946f8dbde8d6f2b4Texas State AGfiled 2026-04-06(4d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/6787d585-07ff-44d9-ad99-347e0f9b6073.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 2, 2026
- Raw hash
- 434c6a75e1d00778474705733244e399c2f28cda89fee3afef192b5e80f584ab
Reporting entity
- Name
- FIVE STATES ENERGY COMPANY, L.L.C.norm: five states energy
- Domain
- fivestates.com
- Industry
- Financial Services
Victim entity
- Name
- FIVE STATES ENERGY COMPANY, L.L.C.norm: five states energy
- Domain
- fivestates.com
- Industry
- Financial Services
- Industry
- Financial Servicesllm
Incident
- Discovered
- Feb 12, 2026
- Materiality determined
- —
- Notification sent
- Mar 26, 2026
- Affected individuals
- 9
- Data types
- PII
- Attack vector
- Unauthorized Access
- Threat actor
- External
Compliance
- Time to disclose
- 7 weeks(49 days from discovery to filing)
- Compliance flags
- ME AG >30d · 49dLeak >30d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Feb 12, 2026→ Filed with AG: Apr 2, 202649d 30 days (soft) ME AG >30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.