Eversource Energy
Incident posture
Linked entities
- Victim
- Eversource Energy
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
Eversource Energy disclosed that phishing and social engineering attacks compromised the credentials of two employees, allowing unauthorized access to limited company data affecting 3,049 customers across Connecticut, Massachusetts and New Hampshire. The accessed information may have included names, mailing and service addresses, account details, phone numbers, email addresses, Social Security numbers, driver's license numbers and financial account information, though the breach did not disrupt electric, gas or water service or involve critical operational systems. The company stated the activity was promptly identified and blocked, additional security measures were implemented, and it has notified state and federal regulators and law enforcement. Affected customers are being offered two years of complimentary credit monitoring and identity theft restoration services.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In April 2026, Eversource Energy experienced phishing and social engineering attacks that compromised the credentials of two employees. The attackers used these compromised accounts to gain limited access to company data. Eversource’s investigation determined that the malicious activity was promptly identified and blocked. Following detection, the company implemented additional security measures to strengthen its cybersecurity systems.
The breach exposed personal information of 3,049 customers across Connecticut, Massachusetts, and New Hampshire. According to a letter from the Connecticut Attorney General’s office obtained by CT Insider, the accessed data varied by customer and may have included names, mailing and service addresses, account information, phone numbers, email addresses, Social Security numbers, driver’s license numbers, and financial account information. Eversource confirmed that the incident did not affect electric, gas, or water service and did not involve customer information systems, critical operational systems, or infrastructure. The affected customers represent a fraction of the utility’s more than 4.6 million customers in its three‑state service territory.
Eversource notified utility regulators in Connecticut, Massachusetts, and New Hampshire, as well as state and federal law enforcement agencies. The company began direct notification to affected customers, providing instructions on how to enroll in two years of complimentary credit monitoring and identity theft restoration services. Eversource stated that the unauthorized access has been blocked and reiterated its commitment to vigilance and appropriate measures to protect against cyber threats and further harden its systems.
Sources
Sources available to members: 2 sources.