People's Energy Data Breach (2020): What Was Exposed & What To Do
The People's Energy Data Breach (2020) (reported December 16, 2020) exposed Dates of birth, Email addresses, Names and Passwords belonging to roughly 359K people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Inside the incident
The breach was reported on 16 December 2020. Public records state that the exposed material included 359,000 unique email addresses together with associated names, phone numbers, physical addresses and dates of birth. Staff email addresses and bcrypt password hashes were also present in the files. No customer passwords were exposed.
Details on the method of access, the precise timeline of the intrusion, and the total number of files involved beyond the reported volume remain undisclosed in available reporting.
How a breach like this happens
Incidents affecting organisations that store customer records frequently begin with the compromise of an internet-facing system, a misconfigured database, or credentials obtained through phishing or prior leaks. Once initial access is gained, an attacker may locate and copy directories containing structured data exports or backups.
Extracted material is sometimes compressed and later posted or sold on forums that specialise in such material. The presence of password hashes rather than plaintext passwords indicates that the organisation had applied some form of hashing to stored credentials, though the hashes themselves can still be subject to offline attacks if weak or reused.
People’s Energy and its sector
People’s Energy operated as a retail energy supplier in the United Kingdom, providing gas and electricity to domestic customers. Companies in this sector routinely collect and retain names, contact details, service addresses, dates of birth for identity verification, and account credentials.
Because energy accounts are tied to physical premises and often involve direct debit or credit arrangements, the data held by such firms can be used to facilitate further contact with individuals or to support impersonation attempts.
What was likely exposed
The reported data types include dates of birth, email addresses, names, phone numbers, physical addresses, and bcrypt password hashes. Staff email addresses were also included. The exact scope of every field contained in the 7GB of files has not been independently verified beyond these categories.
Organisations of this type commonly store additional information such as billing history, meter readings, and payment details; whether any of those categories were present in the exposed material is not confirmed in public statements.
Why it matters
Individuals whose details appear in such incidents may receive unsolicited contact that attempts to exploit the known association with an energy supplier. Email addresses and phone numbers can be used for targeted phishing, while dates of birth and addresses support identity-verification processes elsewhere.
For the organisation, the exposure of staff credentials alongside customer records increases the potential for follow-on attempts to access internal systems. The incident also illustrates the volume of personal data accumulated by utility providers and the consequences when that data leaves the organisation’s control.
If your data was in this breach
People affected should monitor their email accounts for unexpected messages that reference the supplier and consider changing passwords on any other services where the same credentials may have been reused. Enabling multi-factor authentication on important accounts reduces the value of exposed email addresses.
Readers can run a free exposure scan of their email address against known breach data sets to determine whether their information appears in this or other publicly documented incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
More recent breaches
MEO Data Breach (2020)NetGalley Data Breach (2020)MMG Fusion Data Breach (2020)DriveSure Data Breach (2020)Latest breaches
Read GalaxyWarden’s full analysis of the People's Energy Data Breach (2020) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.