DIRECT ENERGY, LP
ent_019e2334bb682c38b357f136298dffc1
Disclosures
9
State AG · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
249,669
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- DIRECT ENERGY, LP
- Normalized
- direct energy— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 54930004WB32WMJUMH55
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
- Corporate parent
- NRG ENERGY, INC.— per GLEIF relationship records
Disclosure history (9)newest first
- California State AGas victim2021-07-12
Direct Energy LP and affiliates experienced a ransomware attack on November 3, 2020, targeting a third-party data analytics vendor. Unauthorized parties accessed and extracted customer files, potentially exposing bank account, credit card, username, password, and SSN data. The vendor did not pay the ransom. Direct Energy suspended the vendor, engaged forensics, notified law enforcement, and offered 24 months of Experian IdentityWorks to affected customers.
- New Hampshire State AGas victim2021-07-02
Direct Energy LP reported a supplemental data breach affecting New Hampshire residents. The incident originated from a ransomware attack on third-party vendor Kitewheel, LLC on November 3, 2020, resulting in the exfiltration of customer data. Affected data includes credit card information (23 residents), bank account information (5 residents), and usernames/passwords (1,163 residents). Direct Energy suspended services with the vendor, reset passwords, notified card networks, and offered credit monitoring.
- California State AGas victim2021-01-21
Direct Energy LP notified customers of a ransomware attack on a third-party data analytics vendor on November 3, 2020. Unauthorized parties accessed and extracted client files containing customer information, potentially including bank account numbers, credit card data, Social Security numbers, and credentials. The vendor did not pay the ransom. Direct Energy suspended activity with the vendor, notified law enforcement and card networks, and offered two years of identity monitoring.
- Maine State AGas victim2021-01-08
Direct Energy LP, including its affiliates First Choice Power, LLC and Home Warranty of America, Inc., reported a data breach affecting 12 Maine residents. The breach, discovered on November 3, 2020, was an external system hack that compromised financial account or card numbers along with their access codes. The company notified affected individuals starting December 2, 2020, and offered 24 months of credit monitoring services through Experian.
- Maine State AGas victim2021-01-06
An external system breach at Direct Energy LP and its affiliates on November 3, 2020, led to the compromise of financial account and/or credit/debit card numbers. The breach affected 12 Maine residents, who were notified and offered 24 months of credit monitoring and identity repair services through Experian.
- Illinois State AGas victim2021-01-01
DIRECT ENERGY LP filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-254). The register records the breach as discovered on December 2, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2020-12-02
Direct Energy LP notified Montana residents of a ransomware attack on a third-party data analytics vendor on November 3, 2020. Unauthorized parties accessed and extracted customer information. Direct Energy suspended the vendor, engaged in forensic investigation, and offered two years of Experian IdentityWorks to affected individuals.
- New Hampshire State AGas victim2020-12-02
Direct Energy LP reported a ransomware attack on its data analytics vendor, Kitewheel, LLC, on November 3, 2020. Unauthorized individuals accessed and extracted client files containing personal information of Direct Energy customers, including usernames, passwords, and payment card/bank account information. Approximately 1,160 New Hampshire residents were affected. Direct Energy suspended activity with the vendor, reset passwords, notified payment processors, and offered two years of credit monitoring.
- Illinois State AGas victim2020-01-01
DIRECT ENERGY LP filed a data-breach notice with the Illinois Attorney General during 2020 (case 20-506). The register records the breach as discovered on November 3, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.