The largest U.S. propane distributor – AmeriGas – has disclosed a data breach that lasted just seconds, but affected 123 company employees and one resident. AmeriGas serves more than 2 million customers across the U.S. and has more than 2,500 distribution locations. The data breach this month was reported by the propane giant to the New Hampshire Attorney General’s Office.
The data breach is said to have originated from JJ Keller, a vendor responsible for providing Department of Transportation (DOT) compliance services to AmeriGas.
These services include assisting AmeriGas in conducting driving record checks, driver drug and alcohol tests, and other regulatory checks mandated by the DOT.

Read also: Cybersecurity: Spending doubled but 2/5 of companies suffer data breaches
On May 10, JJ Keller detected suspicious activity on its systems related to a corporate email account. The company immediately began investigating its network and discovered that a JJ Keller employee had been the victim of a phishing email, which led to his account being compromised.
During their brief access, the malicious actors were able to view certain files that were in the compromised employee’s account. After resetting the employee’s account credentials, JJ Keller immediately launched an investigation to determine the full scope of the breach.
On May 21, JJ Keller notified AmeriGas that the eight-second breach exposed the records of 123 AmeriGas employees. According to JJ Keller, during the eight-second breach, malicious actors gained access to an internal email with spreadsheet attachments containing information for 123 AmeriGas employees, including lab IDs, social security numbers, driver’s license numbers and dates of birth.
See also: Volkswagen/Audi: Data breach affects 3.3 million customers
AmeriGas, in a data breach notification letter dated June 4, 2021, stated the following: “To date, we are not aware of any attempt to misuse this personal data as a result of this incident.”

During the breach, information was also exposed regarding a New Hampshire resident, who was notified of the incident and provided with free credit monitoring services.
At this time, there is no evidence to suggest that any employee information was copied or used.
It is worth mentioning that this is the second data breach incident that occurred at AmeriGas this year.
Proposal: Navistar: Military vehicle manufacturer victim of data breach
In March 2021, AmeriGas disclosed an attempted data breach, in which a company customer service representative was fired for allegedly misusing customer credit card information.

According to the company, some customers who called the company's customer service had verbally disclosed their credit card information to this representative, who may have misused this information to make unauthorized purchases.
At the time, the company said: “We recently discovered that there was an unauthorized disclosure of credit card information to one of our customer service representatives. We do not know if your credit card information was shared, but we write with great caution. We have investigated the issue to further secure your information. The individual involved has been terminated, and we have already implemented additional safeguards.”
Cyberattacks and incidents against critical U.S. energy companies continue to increase , prompting the need for enhanced security controls and awareness training among organizations.
Information source: bleepingcomputer.com
