Reading List

Eversource EV Rebate Program Exposed Massachusetts Customer Data from mtlynch.io RSS feed.

Eversource EV Rebate Program Exposed Massachusetts Customer Data

I recently claimed a rebate for installing an electric vehicle (EV) charger, only to discover that Eversource, my power supplier, was publicly exposing personal information of customers who applied, including:

  • Full names
  • Vehicle registration certificates (including plate number and vehicle identification number)
  • Home addresses
  • Email addresses
  • Phone numbers

I’ll include the backstory that led me to the vulnerability, but if you just want to know about the security vulnerability, you can skip to that.