UK energy company People's Energy has suffered a data breach affecting its entire database , including information about past customers .
The company's co-founder, Karin Sode, told BBC News that sensitive personal information of its customers, including names, addresses, dates of birth, phone numbers and energy meter IDs, was stolen by hackers. After discovering the data breach on the morning of December 16, the company contacted its 270,000 current customers to inform them of the incident. In addition, the hackers gained access to bank accounts and sort codes of 15 small business customers.

The energy company has notified the Information Commissioner's Office (ICO) , the National Cyber Security Centre (NCSC) and the police of the data breach. It is also working with independent experts to investigate how the breach occurred and identify the attackers.
Sode told the BBC: "This attack is a big blow to the company. We want people to feel they can trust us. This was not part of the plan. We are upset and regret the incident. Most of those affected are unlikely to face immediate financial risk, but may be at risk of falling victim phishing attacks in the future.

Paul Bischoff, head of privacy at Comparitech.com, said: “Any data breach is a concern, but we should be particularly concerned about attacks on critical infrastructure. In the coming days, I hope the attacker will be identified so that we know whether it is a government or independent hacker. Fortunately, People's Energy's actual service infrastructure was not affected, and no financial information was stolen for the vast majority of the company's customers. People's Energy customers should be especially vigilant for phishing emails and scams purporting to come from People's Energy or a related company. Cybercriminals may use the personal information stored in the database to personalize emails and make them more convincing. Never click on links or attachments in unsolicited emails, and you should always verify the sender's identity before responding.”
Additionally, Chris Hauk, head of consumer privacy at Pixel Privacy, pointed out that breaches like the one suffered by People's Energy highlight the need for companies large and small to strengthen their systems' defenses against this type of malicious activity.
As Infosecurity Magazine reports, the People's Energy data breach is the latest in a series of similar incidents this year, with the list of victims of these malicious activities including Marriot International, Experian and EasyJet.
