CSIDB logo
Incident

Eversource Energy

Incident posture

Attack window
Apr 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-26 23:52

Linked entities

Victim
Eversource Energy
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Apr 2026
Discovered
Undetermined
Disclosed
Jun 2026
Resolved
Pending

Summary

Eversource Energy disclosed that phishing and social engineering attacks compromised the credentials of two employees, allowing unauthorized access to limited company data affecting 3,049 customers across Connecticut, Massachusetts and New Hampshire. The accessed information may have included names, mailing and service addresses, account details, phone numbers, email addresses, Social Security numbers, driver's license numbers and financial account information, though the breach did not disrupt electric, gas or water service or involve critical operational systems. The company stated the activity was promptly identified and blocked, additional security measures were implemented, and it has notified state and federal regulators and law enforcement. Affected customers are being offered two years of complimentary credit monitoring and identity theft restoration services.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In April 2026, Eversource Energy experienced phishing and social engineering attacks that compromised the credentials of two employees. The attackers used these compromised accounts to gain limited access to company data. Eversource’s investigation determined that the malicious activity was promptly identified and blocked. Following detection, the company implemented additional security measures to strengthen its cybersecurity systems.

The breach exposed personal information of 3,049 customers across Connecticut, Massachusetts, and New Hampshire. According to a letter from the Connecticut Attorney General’s office obtained by CT Insider, the accessed data varied by customer and may have included names, mailing and service addresses, account information, phone numbers, email addresses, Social Security numbers, driver’s license numbers, and financial account information. Eversource confirmed that the incident did not affect electric, gas, or water service and did not involve customer information systems, critical operational systems, or infrastructure. The affected customers represent a fraction of the utility’s more than 4.6 million customers in its three‑state service territory.

Eversource notified utility regulators in Connecticut, Massachusetts, and New Hampshire, as well as state and federal law enforcement agencies. The company began direct notification to affected customers, providing instructions on how to enroll in two years of complimentary credit monitoring and identity theft restoration services. Eversource stated that the unauthorized access has been blocked and reiterated its commitment to vigilance and appropriate measures to protect against cyber threats and further harden its systems.

Sources

Sources available to members: 2 sources.

CSIDB