LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Tibber Data Breach (2024)

MEDIUM severityConfirmedHow we verify

Tibber Data Breach (2024): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·November 10, 2024

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Tibber Data Breach (2024)

Reported November 10, 2024. Approximately 50K people affected.

MEDIUM
Severity
50K
People affected
4
Data types exposed
November 10, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Tibber disclosed a data breach on November 10, 2024, affecting 50,000 customers whose email addresses, names, geographic locations, and purchase records were exposed. Check the company’s status page or your email for guidance on next steps.

Severity & verification
MEDIUM severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Tibber Data Breach (2024) breach?
50K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In November 2024, the German electricity provider Tibber experienced a data breach that exposed personal information belonging to 50,000 customers. The incident, reported on November 10, 2024, involved names, email addresses, geographic locations limited to city and postcode, and total spend on purchases. Public detail remains limited to these confirmed elements, with no further disclosure of how the data was accessed or the full timeline of events.

For customers of an energy supplier that handles household billing and usage data, the exposure of even this subset of records raises practical concerns about identity misuse and targeted outreach. The known scale of 50,000 people affected makes the matter relevant to a substantial portion of Tibber’s customer base in Germany.

Breaking down the breach

According to the available record, Tibber suffered a data breach in November 2024 that resulted in the exposure of personal information for 50,000 customers. The data types confirmed as involved are names, email addresses, geographic locations consisting of city and postcode, and total spend on purchases. The breach was reported on November 10, 2024. No public information has been released about the technical method of intrusion, the precise date range of unauthorized access, whether systems were encrypted or otherwise protected at the time, or any subsequent containment steps taken by the company. The record does not attribute the incident to any named threat actor or group, nor does it describe any ransom demand or public leak-site posting. All that is established is the occurrence itself, the approximate number of people affected, and the categories of data listed above.

How a breach like this happens

Incidents that expose customer records at energy providers typically begin with unauthorized access to systems that store account or billing information. Common pathways include compromised credentials obtained through phishing, exploitation of unpatched software vulnerabilities, or misconfigured cloud storage that leaves databases reachable from the internet. Once inside, an attacker may copy tables containing names, contact details, location fields, and transaction totals before the activity is detected. In many cases the stolen data is later offered for sale or used for further fraud, though the exact sequence after extraction is often never fully documented. Because no specific method has been disclosed for the Tibber incident, these remain general patterns observed across the sector rather than confirmed steps in this particular case. Organizations that handle recurring customer payments and location-linked accounts are frequent targets simply because the data can be monetized quickly.

Who is Tibber?

Tibber is a German electricity provider that supplies power to residential customers and markets related smart-home energy products. Companies in this sector routinely maintain records of customer identities, contact details, service addresses or postcodes, and purchase or consumption history in order to bill for electricity, manage contracts, and deliver usage insights. A breach at such a provider is consequential because energy accounts are long-term relationships that often involve direct debit arrangements and precise household location data. Even limited geographic fields can help map customers to specific neighborhoods, while purchase totals can reveal spending patterns. The combination of identity and financial indicators makes the records useful to criminals seeking to craft convincing scams or open fraudulent accounts elsewhere.

The information in question

The facts state that the exposed data included names, email addresses, geographic locations (city and postcode), and total spend on purchases. These four categories are the only ones confirmed. No additional fields such as full street addresses, phone numbers, payment-card details, meter readings, or account passwords have been named in the public record. Organizations of Tibber’s type typically hold broader datasets—including full billing addresses, bank details for direct debit, and historical consumption figures—but the exact contents of the material taken in this incident remain limited to the four categories listed. Readers should treat any claim of further data types as unconfirmed unless corroborated by official statements.

What's at stake

For the 50,000 people whose records were exposed, the immediate risks are phishing emails that appear legitimate because they reference a real name, city, or recent purchase total, and attempts to open new accounts using the stolen identity details. Geographic location data can also support more targeted social-engineering attempts. For Tibber itself, the breach creates obligations to notify affected customers under applicable data-protection rules, potential regulatory scrutiny, and the longer-term cost of restoring trust among its customer base. Because energy suppliers process recurring payments, any residual risk of account takeover or fraudulent service changes remains a practical concern until customers take protective steps. No financial loss figures or confirmed fraud cases have been publicly tied to this specific incident.

If your data was in this breach

If you are a Tibber customer, begin by reviewing any official notification you may have received from the company and follow the guidance it contains. Change your Tibber account password and enable multi-factor authentication if available. Monitor your email closely for unexpected messages that reference your name, location, or purchase history, and treat unsolicited requests for further personal details with caution. Consider placing a fraud alert with relevant credit-reference agencies if you notice unusual activity. Finally, you can run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets; such a scan provides an independent way to assess whether your details are circulating beyond this single incident.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyTibber security record
74/100
DoxxScan™ · Moderate doxx risk
B 80Good record

1 reported incident on record.

See Tibber’s full breach history →

More recent breaches

Speedio Data Breach (2024)December 24, 2024Young Living Essential Oils Data Breach (2024)December 11, 2024Senior Dating Data Breach (2024)November 23, 2024FlipaClip Data Breach (2024)November 18, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Tibber Data Breach (2024) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram