Direct Energy LP and affiliates experienced a ransomware attack on November 3, 2020, targeting a third-party data analytics vendor. Unauthorized parties accessed and extracted customer files, potentially exposing bank account, credit card, username, password, and SSN data. The vendor did not pay the ransom. Direct Energy suspended the vendor, engaged forensics, notified law enforcement, and offered 24 months of Experian IdentityWorks to affected customers.