DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

NYSEG and RG&E Notify Customers of Unauthorized Access to Customer Data

Posted on January 24, 2012 by Dissent

From NYSEG:

New York State Electric & Gas (NYSEG) and Rochester Gas and Electric (RG&E), subsidiaries of Iberdrola USA, today began sending precautionary notifications to customers advising them of unauthorized access to customer data. This situation involves an employee at an independent software development consulting firm (contracted by NYSEG and RG&E) who allowed unauthorized access to one of the companies’ customer information systems. The customer records contain Social Security numbers, dates of birth and, in some cases, financial institution account numbers.

There is no evidence that any customer data has actually been misused, or that there was any malicious intent. NYSEG and RG&E have consulted with law enforcement and engaged computer forensics experts. The companies’ investigation is ongoing and the companies will continue to provide law enforcement with their full assistance.

“We take our responsibility to protect customer information very seriously and we have robust information technology security measures in place,” said Mark S. Lynch, president of NYSEG and RG&E. “The matter was reported to law enforcement authorities, and as a precautionary measure, we are offering NYSEG and RG&E customers the option of a credit monitoring service at no charge.”

A help line has been established to assist NYSEG and RG&E customers. The help line numbers are 1.877.736.4495 (toll-free) and 1.479.573.7373 (for international callers). The help line will be staffed from 9 a.m. to 9 p.m. (Eastern Time), Monday through Friday, and 11 a.m. to 8 p.m. on Saturday and Sunday.

NYSEG and RG&E have arranged for Experian to offer customers the option of a year of credit monitoring free of charge, to help identify possible fraudulent activity.

Additional information about this matter is available on the companies’ websites at www.nyseg.com and www.rge.com.
###

About NYSEG and RG&E: NYSEG and RG&E are subsidiaries of Iberdrola USA. NYSEG serves 878,000 electricity customers and 261,000 natural gas customers across more than 40% of upstate New York. RG&E serves 367,000 electricity customers and 303,000 natural gas customers in a nine-county region centered on the City of Rochester. Iberdrola USA, a subsidiary of global energy leader Iberdrola, S.A., is an energy services and delivery company with more than 2.4 million customers in upstate New York and New England. We are a team of dedicated individuals working as one to deliver value to our customers, employees and shareholders. By providing outstanding customer service and exceptional reliability, while holding safety and the environment in high regard, we aspire to be a world-class energy company. For more information, visit www.nyseg.com, www.rge.com and www.iberdrolausa.com.

Related: FAQ about the breach and copy of customer notification letter.

Thanks to the reader who alerted me to this breach.

Related posts:

  • Follow-up: Regulators criticize NYSEG for computer security breach
  • NYSEG online hiring site hacked; customers not affected
  • Data Breach at New York Utility Prompts Enforcement Action and Industry-Wide Data Security Review
  • Four Russian Government Employees Charged in Two Historical Hacking Campaigns Targeting Critical Infrastructure Worldwide
Category: Breach IncidentsInsiderMiscellaneousOf NoteU.S.

Post navigation

← Euronet faces first criminal computer breach of secure payment data
Programming Note →

2 thoughts on “NYSEG and RG&E Notify Customers of Unauthorized Access to Customer Data”

  1. Gerry Boz says:
    February 7, 2012 at 4:15 pm

    The NYSEG response has been wholly inadequate. True Experian will monitor my credit cards. However I do not pay my bill by credit card. I pay my bill by check. Experian does not monitor bank accounts. My banks are through-out New York State, in other states and on-line. Experian will not monitor my on-line financial business transactions. They will not monitor my on-line Federal or New York State taxes, not my property taxes, not my retirement accounts, not my life insurance, not my house insurance, not my vehicle insurances and not my charitable beneficence. Although I am the victim of the theft; NYSEG will not give me the name of the company contracted by them, nor the status of perpetrators, nor how many data files where accessed, nor when the breach occurred, nor when they learned of the breach. NYSEG should offer bank account protection through a company, such as ‘Life-Lock’ and on-line protection through a company, such as ‘Carbonite’. NYSEG should have a dedicated telephone line for assistance and facts, with continuing updated information on the standing of this situation. Thank you for listening, I am violated in New York State. g

    1. admin says:
      February 7, 2012 at 5:24 pm

      They claim they “discovered” the breach earlier in January. What they don’t say is how they discovered it nor when it occurred. As far as the name of the software firm, I have no idea why they’re shielding them, but if NYSEG taking responsibility for mitigating harm to you, then your dispute is with them, not the contractor.

      Not for nuthin’ but this could simply be a matter of an employee at the software firm having a technical/coding problem and allowing a buddy access to the database. Still a Bad Thing, but it might not be a situation where people are really at significant risk. Then again…. better to err on the side of caution.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Qantas customers involved in mammoth data breach
  • CMS Sending Letters to 103,000 Medicare beneficiaries whose info was involved in a Medicare.gov breach.
  • Esse Health provides update about April cyberattack and notifies 263,601 people
  • Terrible tales of opsec oversights: How cybercrooks get themselves caught
  • International Criminal Court hit with cyber attack during NATO summit
  • Pembroke Regional Hospital reported canceling appointments due to service delays from “an incident”
  • Iran-linked hackers threaten to release emails allegedly stolen from Trump associates
  • National Health Care Fraud Takedown Results in 324 Defendants Charged in Connection with Over $14.6 Billion in Alleged Fraud
  • Swiss Health Foundation Radix Hit by Cyberattack Affecting Federal Data
  • Russian hackers get 7 and 5 years in prison for large-scale cyber attacks with ransomware, over 60 million euros in bitcoins seized

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The Trump administration is building a national citizenship data system
  • Supreme Court Decision on Age Verification Tramples Free Speech and Undermines Privacy
  • New Jersey Issues Draft Privacy Regulations: The New
  • Hacker helped kill FBI sources, witnesses in El Chapo case, according to watchdog report
  • Germany Wants Apple, Google to Remove DeepSeek From Their App Stores
  • Supreme Court upholds Texas law requiring age verification on porn sites
  • Justices nix Medicaid ‘right’ to choose doctor, defunding Planned Parenthood in South Carolina

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.