2023 National Grid US — CLEAResult MOVEit supply-chain notification; efficiency-program customer metadata
Data compromised
Names, addresses, contact data, and program usage metadata per customer notification summaries—utility portrayed banking credentials as out-of-scope
Technical writeup
Utility press and regional coverage in August 2023 explained that National Grid Massachusetts efficiency-program participants were swept into the Cl0p MOVEit Transfer wave via vendor CLEAResult, which processed rebate paperwork on behalf of multiple New England utilities. HotHardware summarized downstream customer guidance—watch phishing and monitor bills—and pointed to SQLi-class MOVEit CVEs exploited wholesale that summer. CISA AA23-158A documents the May–June 2023 mass exploitation lifecycle tied to those flaws. National Grid corporate statements emphasized no direct penetration of bulk electric-control SCADA but acknowledged program-participant PII exposure categories.
Root cause
Downstream SaaS file-transfer compromise at energy-efficiency contractor using MOVEit