Eversource EV Rebate Program Exposed Massachusetts Customer Data
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A Massachusetts utility company's EV rebate portal exposed customer personal information—including names, addresses, vehicle registration details, and VINs—through unauthenticated API endpoints. The vulnerability allowed anyone to access and potentially modify rebate applications by simply removing authentication cookies from
Table of contents
Why is this rebate process so complicated? 🔗︎We need your charger’s MAC address 🔗︎No, that’s wrong. Do it again 🔗︎The perverse incentives of Eversource’s EV rebate program 🔗︎Eversource leaking customer records 🔗︎What if a malicious user changes my application? 🔗︎Reporting the vulnerability 🔗︎What Massachusetts residents can do 🔗︎Sort: