[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3eqze5ouisla3":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":11,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":26,"seoTitle":14,"seoTitleEn":27,"seoDescription":14,"seoDescriptionEn":28,"logoUrl":29,"isVerified":4,"isSensitive":4,"isSpamList":30,"isMalware":30,"company":31},"68e3266eda11adda488253c4","tibber","Tibber Data Breach","tibber.com","2024-11-10T00:00:00.000Z","2024-12-14T06:49:41.000Z","2026-07-18T23:59:30.443Z","Third party breach","",[],50002,"known",null,"unknown","Medium",[22,23,24,25],"Email addresses","Geographic locations","Names","Purchases","\u003Cp>The Tibber data breach is a security incident recorded in November 2024 that affected approximately 50,000 accounts. In the incident associated with the German electricity provider, customer identity, location, and purchase spending fields were exposed. This content has been prepared to clearly help users understand which data fields are at risk and which security measures should be prioritized.\u003C\u002Fp>\u003Cp>In the context of an energy customer, the city, postal code, and total expenditure information can provide signals about the household and consumption profile. Only verifiable data classes are used in the text; unverified additional claims, different events, or similarly named services are not consolidated under this record. This way, the explanation remains both useful to the user and a non-misleading assessment.\u003C\u002Fp>\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\u003Cp>The types of data listed in this incident are: email addresses, geographic locations, names, and purchase information. Energy consumption and location data can make fake invoices or customer service messages more convincing. The association of multiple fields with the same user can make attackers' attempts at fake notifications, account recovery, social engineering, or identity correlation more credible.\u003C\u002Fp>\u003Cp>In this record, the password field is not listed; the risk focuses on energy account, billing, and customer communication. If there are fields such as password, password hint, private message, official ID, financial information, location, or profile photo, the risk is not limited to email spam. Even in records without a password, phone, address, IP, date of birth, or social profile information can be used in targeted attacks.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The record covers approximately 50,000 customer records associated with the domain tibber.com. The incident is classified as a confirmed record. The scope has been written by individually checking the account number, domain name, country, sector, and data classes. Data types that are not listed have not been shown as if they exist for the user.\u003C\u002Fp>\u003Cp>The sector has been corrected to energy and electricity supply. In some cases, the company response has different contexts such as third-party service, forum account, newsletter list, or user profile. These records have been separated individually, not duplicated, and the actual service context of the incident has been preserved.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>Tibber customers, individuals with an energy service account, and users who can be targeted by city\u002Fpostal code are at risk. The main risk for these users is that leaked data can be matched with information used on other platforms. If the same email, username, phone number, IP, address, or password is repeated across different accounts, attackers can exploit these common identifiers.\u003C\u002Fp>\u003Cp>The energy context can be misused in fake invoice, meter, payment, discount, or subscription verification messages. Different contexts such as forums, games, recipes, accommodation, energy, event tickets, newsletters, social media, and finance generate different risks. The user should consider not only the data fields but also which service these fields are associated with.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Affected users should verify invoice and payment messages through the official channel and check the security of their account email. If a password or password hint has been listed, users should change it on all accounts where the same or similar password is used, use a unique password, and enable multi-factor authentication wherever possible. The security of the email account should also be checked.\u003C\u002Fp>\u003Cp>Users should check account recovery options, login history, forwarding rules, and suspicious notifications in records containing phone, address, location, date of birth, private message, social profile, or financial information. Individuals with corporate or publicly visible profiles should also consider the risk of targeted messages and reputation.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Strong verification in energy calculations, checking invoice notifications, and limiting old customer data are important. In the long term, a password manager, unique password, multi-factor authentication, closing old accounts, and reducing unnecessary profile information are the fundamental defense. Since permanent personal data cannot be changed, user behavior and account settings should be strengthened.\u003C\u002Fp>\u003Cp>For institutions, these events show that backup file accesses, forum account permissions, newsletter subscription data, customer data retention periods, and notification processes need to be regularly audited. For users, not repeating the same identity information across different services and verifying unexpected messages through a second channel provides lasting protection.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>If the user matches with this record, they should check suspicious notifications in their energy account and email account. If a match is observed, the user should first read which data fields are listed, then prioritize the steps accordingly. If there is a password, password change should be prioritized; if there is financial data, account monitoring; if there are private messages or social profiles, privacy control; if there is a location, physical security assessment should be prioritized.\u003C\u002Fp>\u003Cp>Final assessment: Although this record does not contain a password, it has been considered sensitive customer data due to energy consumption, location, and spending context. The user should compare this record with their account history; they should separately check the services where they use the same email, phone, username, address, or password. Any suspicious call, email, message, or account recovery notification should be considered higher risk after the incident.\u003C\u002Fp>","Tibber Data Breach (50 Thousand Reported Records)","Tibber Data Breach. 50 Thousand reported records were reported. Reported data: Email addresses, Geographic locations, Names. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Ftibber_com.webp",false,{"name":32,"sector":33,"country":34,"website":9,"websiteArchiveUrl":14,"websiteStatus":14,"websiteCheckedAt":18},"Tibber","Energy \u002F Electricity Provider","Germany"]