Eversource EV Rebate Program Exposed Massachusetts Customer Data
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A Massachusetts utility company's EV rebate portal exposed customer personal information—including names, addresses, vehicle registration details, and VINs—through unauthenticated API endpoints. The vulnerability allowed anyone to access and potentially modify rebate applications by simply removing authentication cookies from HTTP requests. The issue was discovered during a frustrating rebate claim process that required excessive documentation and had perverse incentives, as the utility had no stake in approving claims once customers had already purchased EVs. The vendor responded quickly to fix the reported vulnerabilities within 24 hours.