Green Mountain Power Data Breach Exposes Social Security Numbers and Financial Account Information

Published: 9 September 2026
Energy data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Green Mountain Power notified the Vermont Attorney General in September 2026 that hackers accessed customer Social Security numbers, financial account codes, and credit or debit card information. The exact number of people affected has not been disclosed. Affected individuals should freeze their credit immediately and monitor financial accounts closely for suspicious activity.

CompanyGreen Mountain Power
IndustryEnergy
Data Types ExposedSocial Security Numbers, Financial Account Codes, Credit and Debit Account Information
People AffectedNot Publicly Disclosed
Attack MethodUnspecified/Unauthorized Access
Regulators NotifiedVermont Attorney General

What Happened in the Green Mountain Power Data Breach?

Green Mountain Power recently confirmed a data breach affecting sensitive customer information. The company filed a formal notification with the Vermont Attorney General’s office in September 2026. This filing revealed that unauthorized parties gained access to personal data belonging to its customers.

According to the notification, the exposed information includes Social Security numbers, financial account codes, and credit and debit card details. As a result, affected individuals now face real risks tied to identity theft and financial fraud. The exact date the breach was discovered has not been publicly disclosed.

Details about how the intrusion occurred have not been made public either. However, because the company chose to notify a state regulator, this indicates that an investigation confirmed actual access to personal records. Green Mountain Power likely worked with forensic security experts to determine the scope of the incident before notifying affected residents. This kind of investigation typically takes weeks or months to complete properly.

Who was affected?

The breach appears to primarily affect customers of Green Mountain Power, Vermont’s largest electric utility. Because utility companies maintain extensive records for billing and account management, customers who pay bills or manage accounts online may be impacted. In addition, anyone who has ever provided payment information to the company could be at risk.

The exact number of individuals affected by this breach has not been publicly disclosed. Therefore, it remains unclear whether the breach touched a small subset of customers or a much larger portion of the utility’s customer base. Given that Green Mountain Power serves residential and commercial customers throughout Vermont, the geographic scope is likely concentrated within the state. Still, some affected individuals may live elsewhere if they previously held accounts in Vermont.

What Information Was Potentially Exposed?

The Vermont Attorney General filing specifies exactly which categories of personal data were involved in this incident. This information is highly sensitive because it can be used to commit fraud or open new accounts in a victim’s name. Below is a list of the confirmed data types.

  • Social Security numbers
  • Financial account codes
  • Credit and debit account information

This combination of data is particularly dangerous because it gives criminals nearly everything needed to impersonate a victim financially. For example, a Social Security number paired with financial account details can allow fraudsters to open new lines of credit. In addition, they could file fraudulent tax returns or apply for loans using a victim’s identity.

Meanwhile, exposed credit and debit account information creates a more immediate risk. Criminals could use these details to make unauthorized purchases or drain existing accounts. As a result, affected customers should watch their financial statements closely in the coming months, since this type of fraud often happens quickly after a breach becomes known to attackers.

What is the company doing?

In response to the breach, Green Mountain Power submitted a formal notification to state regulators. This step is required under Vermont’s data breach notification law once a company confirms unauthorized access to residents’ personal information. The company also filed formal notification with the Vermont Attorney General.

Beyond regulatory notification, companies in this situation typically notify affected customers directly by mail or email. They often also offer free credit monitoring or identity theft protection services for a limited period. Although specific remediation offers from Green Mountain Power have not been detailed publicly, affected customers should watch for official communication from the company regarding any protective services provided.

Additionally, the company likely reviewed its network security systems following the discovery of this incident. This kind of review often leads to updated security protocols to prevent similar incidents going forward. Utility companies handling sensitive payment data face increasing pressure to strengthen their cybersecurity defenses.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should request a free copy of their credit report from each of the three major credit bureaus. Because Social Security numbers were involved in this breach, new account fraud is a genuine concern. Reviewing your reports regularly helps you catch unfamiliar accounts or inquiries early.

You can access free weekly credit reports through AnnualCreditReport.com. In addition, consider setting up recurring reminders to check your reports every few months going forward. This ongoing habit can help you spot suspicious activity long after the initial breach headlines fade.

Consider a Credit Freeze or Fraud Alert

Because this breach exposed Social Security numbers and financial account codes, a credit freeze is strongly recommended. A freeze prevents new creditors from accessing your credit file, which stops most fraudulent account openings before they start. You can request a freeze for free with each credit bureau individually.

Alternatively, a fraud alert offers a lighter layer of protection. It requires lenders to verify your identity before extending credit in your name. Either option significantly reduces the odds that a criminal can successfully use your stolen information to open new accounts.

Watch for Phishing Attempts

Following a breach like this, scammers often send fake emails or texts pretending to be from the breached company. These messages frequently try to trick victims into revealing more personal information. Therefore, never click links or provide details in response to unsolicited messages claiming to be from Green Mountain Power.

Instead, contact the company directly using a phone number or website you already know is legitimate. This simple step can prevent a bad situation from becoming worse. Because scammers often use current events like this breach as bait, staying alert to unexpected messages is essential for the coming months.

Review Financial and Utility Accounts Closely

Since credit and debit account information was exposed, affected individuals should carefully review recent bank and card statements. Look for any charges you don’t recognize, even small ones, since fraudsters sometimes test stolen card details with tiny transactions first. Report anything suspicious to your bank immediately.

Furthermore, consider reviewing your Green Mountain Power account itself for any unusual changes. This includes checking for altered payment methods or unfamiliar account activity. If you notice anything unexpected, contact the company’s customer service department right away to secure your account.



More Information

View the public data breach notification listing from Vermont Attorney General

Related Data Breaches

Browse all recent data breaches →