---
title: "Eversource EV Rebate Program Exposed Massachusetts Customer Data"
url: https://daily.dev/posts/eversource-ev-rebate-program-exposed-massachusetts-customer-data-bc7aqzbd9
source_url: https://mtlynch.io/eversource-resource-innovations-exposure/
type: article
source: "Michael Lynch"
published: 2026-02-09T21:05:36.768Z
updated: 2026-02-09T21:06:00.869Z
tags: ["security", "authentication", "data-breach"]
reading_time: 14
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Eversource EV Rebate Program Exposed Massachusetts Customer Data

**[Michael Lynch](https://daily.dev/sources/mtlynch)** · 14 min read · 0 upvotes · 0 comments

## Summary

A Massachusetts utility company's EV rebate portal exposed customer personal information—including names, addresses, vehicle registration details, and VINs—through unauthenticated API endpoints. The vulnerability allowed anyone to access and potentially modify rebate applications by simply removing authentication cookies from HTTP requests. The issue was discovered during a frustrating rebate claim process that required excessive documentation and had perverse incentives, as the utility had no stake in approving claims once customers had already purchased EVs. The vendor responded quickly to fix the reported vulnerabilities within 24 hours.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://mtlynch.io/eversource-resource-innovations-exposure/>

## Similar posts on daily.dev

- [EV charging biz zaps customers with data leak scare](https://daily.dev/posts/ev-charging-biz-zaps-customers-with-data-leak-scare-iedquppsw) · The Register · 0 upvotes · 0 comments
- [Crims hit EV charger firm ELECQ, steal customer contact data](https://daily.dev/posts/crims-hit-ev-charger-firm-elecq-steal-customer-contact-data-moqicvuwt) · The Register · 0 upvotes · 0 comments
- [Exploiting Volvo/Eicher's fleet platform to gain control over all users/vehicles](https://daily.dev/posts/exploiting-volvo-eicher-s-fleet-platform-to-gain-control-over-all-users-vehicles-gkfj0eqmw) · Hacker News · 0 upvotes · 0 comments
- [Tata Motors confirms it fixed security flaws, which exposed company and customer data](https://daily.dev/posts/tata-motors-confirms-it-fixed-security-flaws-which-exposed-company-and-customer-data-s4j3kmewp) · TechCrunch · 0 upvotes · 0 comments
- [Online attackers take Renault UK customer data for a joyride](https://daily.dev/posts/online-attackers-take-renault-uk-customer-data-for-a-joyride-wjnmdoneo) · The Register · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#authentication](https://daily.dev/tags/authentication), [#data-breach](https://daily.dev/tags/data-breach)

[View this post on daily.dev](https://daily.dev/posts/eversource-ev-rebate-program-exposed-massachusetts-customer-data-bc7aqzbd9)
