About UsCareersBlogLog In
Cyber Security ResourceCyber Security Resource
  • Home
  • Products
    • IT Security Partnership Program
    • Cyber Security Resource Community
    • Third Party Risk Management
    • Managed Detection and Response
  • Services
    • Cyber Security Risk Assessment
    • HITRUST Readiness Assessment
    • Cyber Security Advisory Services
    • Penetration Test
    • Vulnerability Assessment
  • Solutions
    • Security Awareness & Training
    • Email Phishing
    • Antivirus – Antimalware
  • Resources
    • Cyber Security Resource Library
    • IT Governance
    • Information Security
    • Risk Management
    • Vulnerability Management
    • Incident Response
  • Partners
    • Consultants Network
    • Sales Partners
Facebook
Twitter
LinkedIn
YouTube
About UsCareersBlogLog In

Eversource Energy Data Breach: Due to Unsecured Cloud Storage

April 22, 2021AddMgrNo Comments
New England’s largest energy provider, Eversource experienced a data breach after sensitive details of customers were exposed on an unsecured cloud server. Eversource Energy is New England’s latest energy provider, supplying 4.3 million electric and natural gas customers across Connecticut, Massachusetts, and New Hampshire.
According to a data breach notice shared with BleepingComputer, Eversource Energy is warning customers that their name, address, phone number, social security number, service address, and account number were exposed due to an unsecured cloud storage server. Eversource is also providing a free one-year identity monitoring service via Cyberscout to those who have been affected by the data breach.
Eversource claims that there is no evidence that any of this information was obtained or misused by unauthorized individuals at this time. Although this is possible, BleepingComputer suggests that users sign up for Eversource’s free identity theft monitoring to be which notify the users if their social security number is used fraudulently. 
When the Eversource customer called Cyberscout to learn more about the data breach after receiving the breach notice. They were eventually sent an internal frequently asked questions (FAQ) guide, which Cyberscout employees used to respond to questions about the breach. 
According to the FAQ shared with BleepingComputer, Eversource conducted a security review on March 16th and discovered an “internet data storage folder” that was misconfigured, allowing anyone to access its contents. They immediately protected the unsecured folder after discovering it and started investigating what data was stored on it. 
The unsecured folder comprised of unencrypted files containing the personal details of 11,000 Eversource eastern Massachusetts customers which were created in August 2019.
Affected users should also be on the lookout for phishing emails posing as Eversource or other companies and harvesting additional details using the exposed data. 
Several utility firms, including EDP Renewables North America, Centrais Eletricas Brasileiras (Eletrobras), Companhia Paranaense de Energia (Copel), and the Enel Group, have been attacked by ransomware attacks and network breaches in the last two years.
Threat perpetrators recently breached a water treatment plant in Oldsmar, Florida, and attempted to raise the sodium hydroxide (NaOH) cleanser concentration to dangerous levels. 
These breaches, as well as EverSource’s less destructive breach, highlight the need for utilities to improve their security posture in order to avoid potential leaks and attacks.

This post was originally published on this site

AddMgr
Our passion at Cyber Security Resource is to work with IT Security Officers, Risk Managers, IT Managers, and Business Professionals to meet their Compliance and IT Security requirements. We offer IT security risk assessments, network and application penetration testing, and security certification readiness for Hitrust or SOCII.
Previous post America’s Cyberwar: Zero Days, Espionage & Vulnerabilities | Meet The Press | NBC News Next post Microsoft President: Doesn’t Feel Like A Time Of Peace On Cyber Attacks | Meet The Press | NBC News

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Get Our Newsletter

  • Virtual CISO Advisory Services
  • Cyber Security Risk Assessment
  • Vulnerability Assessment
  • Penetration Test
  • Cyber Security Awareness Training

Latest News

  • HITRUST Certification vs HIPAA: What you Need to Know
  • Why Do Businesses Need an Incident Response Plan?
  • Vulnerability Assessment vs. Penetration Testing: What’s the Difference?
  • Healthcare Cyber Security Trends: What You Need to Know Now and Going Forward
  • How To Perform a Cyber Security Risk Analysis For Any Organization.
HomeAccountPrivacy PolicyReturn & Refund PolicyTerms and ConditionsAbout UsContact Us

Return & Refund Policy - Terms and Conditions