Electric Ireland says contractor staff member accessed 8,000 customers' data

Organization
Electric Ireland
Exploit
Malicious Insider
Industry
Energy

Electric Ireland, the retail supply arm of the Irish state utility ESB, confirmed on November 8, 2023 that a small proportion of its 1.1 million residential accounts may have been compromised. The supplier said an employee of a company working on its behalf may have inappropriately accessed customer data, potentially enabling misuse of personal and financial information. Around 8,000 accounts were affected.

The information at risk included the credit and debit card details customers had given Electric Ireland to pay bills, along with names, addresses, email addresses, phone numbers, dates of birth and bank account details. RTE reported that Electric Ireland advised affected customers to cancel the cards used for bill payments and to review bank and card statements going back to October 2021 for unfamiliar activity.

The company wrote to every potentially affected customer with instructions, and stressed that anyone who had not received a letter needed to take no action. It also asked affected customers to contact their banks, change passwords, monitor accounts and avoid engaging with unsolicited calls.

The Garda National Cyber Crime Bureau identified the suspected breach and referred it to the Garda National Economic Crime Bureau, which contacted Electric Ireland immediately. Electric Ireland reported the matter to Ireland's Data Protection Commission and said it was liaising with the commission and An Garda Siochana. The company said it would pass any reports of fraudulent activity to gardai. Both engagements were ongoing when the incident was made public.

Sources