CSIDB logo
Incident

Dominion Resources

Incident posture

Attack window
Mar 2014
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-01-20 18:15

Linked entities

Victim
Dominion Resources
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2014
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity breach at a subcontractor, Onsite Health Diagnostics, compromised personal information of approximately 1,700 individuals enrolled in Dominion Resources' employee wellness program, including employees, spouses, and domestic partners. The attacker accessed names, addresses, email addresses, phone numbers, genders, dates of birth, and encrypted system passwords stored by the subcontractor. Dominion notified affected individuals, recommended username and password changes, provided complimentary credit monitoring, and terminated its relationship with the subcontractor. The intrusion was discovered months after initial access, with delayed notifications to the wellness program vendor and Dominion. The company emphasized a thorough review of vendor security practices following the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In March 2014, an attacker breached systems belonging to Onsite Health Diagnostics, a subcontractor handling online health-screening appointments for Dominion Resources' employee wellness program. The intrusion, which occurred on March 25, exposed personal information of approximately 1,700 individuals associated with Dominion Resources, including employees and their spouses or domestic partners who had scheduled appointments through the system. Compromised data consisted of names, addresses, email addresses, phone numbers, genders, dates of birth, and encrypted passwords used for Onsite Health Diagnostics' platform. The breach remained undetected for nearly three months before discovery. Dominion Resources, a Virginia-based energy company, was not directly compromised, as the incident originated within its subcontractor's infrastructure.

Onsite Health Diagnostics notified StayWell Health Management, Dominion's wellness program vendor, about the breach on June 16, 2014. Dominion Resources learned of the incident eight days later on June 24, with specific identities of affected individuals confirmed by July 7. The company promptly notified all impacted parties and advised them to change their usernames and passwords as a precautionary measure. Dominion also offered affected individuals complimentary credit monitoring services for one year. As a direct consequence of the breach, Dominion terminated its relationship with Onsite Health Diagnostics for scheduling services. Company spokesperson C. Ryan Frazier confirmed Dominion was conducting a thorough review of all similar vendor relationships to assess security practices. The delayed discovery timeline—from March intrusion to July notifications—highlighted vulnerabilities in third-party system monitoring.

Sources

Sources available to members: 1 source.

CSIDB