DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

NYSEG and RG&E Notify Customers of Unauthorized Access to Customer Data

Posted on January 24, 2012 by Dissent

From NYSEG:

New York State Electric & Gas (NYSEG) and Rochester Gas and Electric (RG&E), subsidiaries of Iberdrola USA, today began sending precautionary notifications to customers advising them of unauthorized access to customer data. This situation involves an employee at an independent software development consulting firm (contracted by NYSEG and RG&E) who allowed unauthorized access to one of the companies’ customer information systems. The customer records contain Social Security numbers, dates of birth and, in some cases, financial institution account numbers.

There is no evidence that any customer data has actually been misused, or that there was any malicious intent. NYSEG and RG&E have consulted with law enforcement and engaged computer forensics experts. The companies’ investigation is ongoing and the companies will continue to provide law enforcement with their full assistance.

“We take our responsibility to protect customer information very seriously and we have robust information technology security measures in place,” said Mark S. Lynch, president of NYSEG and RG&E. “The matter was reported to law enforcement authorities, and as a precautionary measure, we are offering NYSEG and RG&E customers the option of a credit monitoring service at no charge.”

A help line has been established to assist NYSEG and RG&E customers. The help line numbers are 1.877.736.4495 (toll-free) and 1.479.573.7373 (for international callers). The help line will be staffed from 9 a.m. to 9 p.m. (Eastern Time), Monday through Friday, and 11 a.m. to 8 p.m. on Saturday and Sunday.

NYSEG and RG&E have arranged for Experian to offer customers the option of a year of credit monitoring free of charge, to help identify possible fraudulent activity.

Additional information about this matter is available on the companies’ websites at www.nyseg.com and www.rge.com.
###

About NYSEG and RG&E: NYSEG and RG&E are subsidiaries of Iberdrola USA. NYSEG serves 878,000 electricity customers and 261,000 natural gas customers across more than 40% of upstate New York. RG&E serves 367,000 electricity customers and 303,000 natural gas customers in a nine-county region centered on the City of Rochester. Iberdrola USA, a subsidiary of global energy leader Iberdrola, S.A., is an energy services and delivery company with more than 2.4 million customers in upstate New York and New England. We are a team of dedicated individuals working as one to deliver value to our customers, employees and shareholders. By providing outstanding customer service and exceptional reliability, while holding safety and the environment in high regard, we aspire to be a world-class energy company. For more information, visit www.nyseg.com, www.rge.com and www.iberdrolausa.com.

Related: FAQ about the breach and copy of customer notification letter.

Thanks to the reader who alerted me to this breach.

Category: Breach IncidentsInsiderMiscellaneousOf NoteU.S.

Post navigation

← Euronet faces first criminal computer breach of secure payment data
Programming Note →

2 thoughts on “NYSEG and RG&E Notify Customers of Unauthorized Access to Customer Data”

  1. Gerry Boz says:
    February 7, 2012 at 4:15 pm

    The NYSEG response has been wholly inadequate. True Experian will monitor my credit cards. However I do not pay my bill by credit card. I pay my bill by check. Experian does not monitor bank accounts. My banks are through-out New York State, in other states and on-line. Experian will not monitor my on-line financial business transactions. They will not monitor my on-line Federal or New York State taxes, not my property taxes, not my retirement accounts, not my life insurance, not my house insurance, not my vehicle insurances and not my charitable beneficence. Although I am the victim of the theft; NYSEG will not give me the name of the company contracted by them, nor the status of perpetrators, nor how many data files where accessed, nor when the breach occurred, nor when they learned of the breach. NYSEG should offer bank account protection through a company, such as ‘Life-Lock’ and on-line protection through a company, such as ‘Carbonite’. NYSEG should have a dedicated telephone line for assistance and facts, with continuing updated information on the standing of this situation. Thank you for listening, I am violated in New York State. g

    1. admin says:
      February 7, 2012 at 5:24 pm

      They claim they “discovered” the breach earlier in January. What they don’t say is how they discovered it nor when it occurred. As far as the name of the software firm, I have no idea why they’re shielding them, but if NYSEG taking responsibility for mitigating harm to you, then your dispute is with them, not the contractor.

      Not for nuthin’ but this could simply be a matter of an employee at the software firm having a technical/coding problem and allowing a buddy access to the database. Still a Bad Thing, but it might not be a situation where people are really at significant risk. Then again…. better to err on the side of caution.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Lower Merion School District says a data breach was caused by a computer glitch
  • After $1 Million Ransom Demand, Virgin Islands Lottery Restores Operations Without Paying Hackers
  • Junior Defence Contractor Arrested For Leaking Indian Naval Secrets To Suspected Pakistani Spies
  • Mysterious leaker GangExposed outs Conti kingpins in massive ransomware data dump
  • Resource: HoganLovells Asia-Pacific Data, Privacy and Cybersecurity Guide 2025
  • Class action settlement following ransomware attack will cost Fred Hutchinson Cancer Center about $52 million
  • Comstar LLC agrees to corrective action plan and fine to settle HHS OCR charges
  • Australian ransomware victims now must tell the government if they pay up
  • U.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams
  • Victoria’s Secret takes down website after security incident

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Fears Grow Over ICE’s Reach Into Schools
  • Resource: HoganLovells Asia-Pacific Data, Privacy and Cybersecurity Guide 2025
  • She Got an Abortion. So A Texas Cop Used 83,000 Cameras to Track Her Down.
  • Why AI May Be Listening In on Your Next Doctor’s Appointment
  • Watch out for activist judges trying to deprive us of our rights to safe reproductive healthcare
  • Nebraska Bans Minor Social Media Accounts Without Parental Consent
  • Trump Taps Palantir to Compile Data on Americans

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.