Regional

FirstEnergy locks online accounts, requires new passwords after hack attempt

Brian C. Rittmeyer
By Brian C. Rittmeyer
2 Min Read Sept. 5, 2021 | 4 years Ago
Go Ad-Free today

West Penn Power parent FirstEnergy locked all of its customers online accounts Friday after a large scale attempt to break into them, a spokeswoman for the electric utility said Sunday.

There was no evidence that any information was accessed, altered or taken from customer accounts, which number in the millions, and there was no threat or impact to electric service, FirstEnergy spokeswoman Jennifer Young said.

No sensitive customer information, such as complete bank account or credit card information, is available through the online accounts, according to the company.

Customers were being contacted by email with instructions to reset their account passwords.

While routinely monitoring its website and customer online accounts, Young said FirstEnergy recently detected a large number of attempts to log into customer accounts using usernames and passwords that appeared to come from a source outside the company. While most of the attempts were not successful, Young said an unknown number of unauthorized logins were completed.

Among the accounts where login attempts were successful, Young said there were no signs that those who did so accessed the account information that is available.

Young said the attack is known as “credential stuffing,” where someone buys a list of potential usernames and passwords on the dark web and tries to use them on a large number of companies’ online accounts to see what works.

Most of the usernames and passwords that were attempted to be used are not for FistEnergy accounts, she said.

She did not know if the attempts had stopped or if they were ongoing.

Share

Categories:

Tags:

About the Writers

Brian C. Rittmeyer, a Pittsburgh native and graduate of Penn State University's Schreyer Honors College, has been with the Trib since December 2000. He can be reached at brittmeyer@triblive.com.

Article Details

Password tips FirstEnergy is requiring its customers with online accounts to reset their passwords after a large scale attempt to…

Password tips
FirstEnergy is requiring its customers with online accounts to reset their passwords after a large scale attempt to break into them. The utility is asking customers to follow best practices for setting passwords, including:
• Do not reuse old passwords.
• Do not use the same password for multiple online accounts; every password should be unique.
• Do not reveal your password to others.
• Do not use words that can be found in the dictionary.
• Follow the complexity requirements of the website, such as length of password and required use of special characters.
• Do not use passwords that contain information about you, such as a birthday.

Push Notifications

Get news alerts first, right in your browser.

Enable Notifications

Content you may have missed

Enjoy TribLIVE, Uninterrupted.

Support our journalism and get an ad-free experience on all your devices.

  • TribLIVE AdFree Monthly

    • Unlimited ad-free articles
    • Pay just $4.99 for your first month
  • TribLIVE AdFree Annually BEST VALUE

    • Unlimited ad-free articles
    • Billed annually, $49.99 for the first year
    • Save 50% on your first year
Get Ad-Free Access Now View other subscription options