Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Eversource Energy Data Breach Caused By Unsecured Cloud Storage

Eversource Energy Data Breach Caused By Unsecured Cloud Storage

Eversource, the largest energy supplier in New England, has suffered a data breach after customers’ personal information was exposed on an unsecured cloud server.

Eversource Energy is the latest energy delivery company in New England, powering 4.3 million electric and natural gas customers throughout Connecticut, Massachusetts, and New Hampshire.

In a data breach notification shared with BleepingComputer, Eversource Energy is warning customers that the unsecured cloud storage server exposed their name, address, phone number, social security number, service address, and account number.

Eversource data breach notification
Eversource data breach notification

Also Read: What Does A Data Protection Officer Do? 5 Main Things

For those affected by the data breach, Eversource is offering a free 1-year identity monitoring service through Cyberscout.

After receiving the data breach notification, an Eversource customer called Cyberscout to learn more about the breach. Ultimately, they were sent an internal frequently asked questions document used by Cyberscout employees to answer inquiries about the breach.

According to the FAQ shared with BleepingComputer, Eversource performed a security review on March 16th and found a “cloud data storage folder” that was misconfigured so that anyone could access its contents. When they discovered the unsecured folder, they immediately secured it and began investigating what data was stored on the folder.

This folder contained unencrypted files created in August 2019 that included the personal information of 11,000 Eversource eastern Massachusetts customers.

At this time, Eversource states that there is no indication that any of this data was acquired or misused by unauthorized people.

While this may be true, BleepingComputer recommends that users sign up for the free identify theft monitoring offered by Eversource to be alerted if their social security number is fraudulently used.

Affected users should also be on the lookout for possible phishing emails pretending to be from Eversource, or other companies, that utilize the exposed data to harvest further information.

Over the past two years, ransomware attacks and network breaches have targeted numerous utility companies, including EDP Renewables North America, Centrais Eletricas Brasileiras (Eletrobras) and Companhia Paranaense de Energia (Copel), and the Enel Group.

Even more concerning, threat actors recently breached a water treatment system in Oldsmar, Florida, and attempted to increase the concentration of sodium hydroxide (NaOH) cleanser to hazardous levels

These breaches, and even EverSource’s less malicious breach, underscore how utilities need to increase their security posture to prevent these types of leaks and attacks in the future.

Also Read: The DNC Registry Singapore: 5 Things You Must Know

Thx to webster341 and i486DX for sharing their notifications and the FAQ.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us