On November 1, 2024, energy-services provider Arctrade appeared on the leak site operated by the Everest ransomware group. The listing states that internal files were exfiltrated during a ransomware attack and claims the data includes information on more than 40,000 customers along with details such as ISO, State, LDC, Load Zone, Customer, LDC Acct ID #, Account Group, Is Special Needs, Is Switch Hold, Customer Added Date, Last Upload Date, Current Status, and multiple contract-related fields.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Arctrade
Get alerted the next time Arctrade files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Arctrade’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The Everest leak site lists Arctrade at its .onion address and indicates the company was hit by a ransomware operation. It explicitly notes that internal files were allegedly exfiltrated and highlights the presence of more than 40,000 customer records containing the data fields listed above. The disclosure does not specify the exact number of records ultimately published, the size of the stolen archive, or whether any proof files have been released beyond the initial sample. The notification also does not state when the intrusion occurred or how long the attackers maintained access before exfiltration.
Why This Matters for You and Your Family
If you or anyone in your household has an electricity or natural-gas account with Arctrade or one of its partners, your personal and account details may now sit in a ransomware repository. More than 40,000 customers are referenced in the listing, which means the breach touches ordinary households rather than only commercial clients. The exposed fields include account numbers, contract start and end dates, rate information, special-needs flags, and switch-hold status — data that can be combined with publicly available records to build a detailed profile of your energy usage, billing history, and home address. Once attackers or data resellers possess this information, it can be sold on underground forums or used to support further fraud such as utility takeovers, tax-refund scams, or targeted phishing campaigns that appear to come from your energy provider.
Doxxing and Identity-Chain Risks
Energy-provider records are high-value connectors in doxxing chains because they tie real names, service addresses, and account identifiers to other online handles. A single leaked LDC Account ID or contract document can be cross-referenced with gaming usernames, email addresses, or phone numbers that appear in earlier breaches, allowing attackers to map an entire household. Credential leaks of this type frequently cascade into account takeovers on gaming platforms, where children’s accounts become entry points for harassment or further extortion. The longer the data remains available on the Everest site or its mirrors, the higher the chance that multiple criminal groups will obtain copies and begin building persistent identity profiles that are difficult to dismantle without coordinated effort.