Skip to content

Customer Data from Netze BW and Stuttgart Netze Exposed via Compromised Service Provider

The Point: External service providers with access to customer data represent an established attack vector, enabling highly convincing phishing and fraud attempts.

A cyberattack on an external IT service provider has exposed customer data from Netze BW and Stuttgart Netze. Thousands of households that had new electricity meters installed through the affected company are impacted.

A cyberattack on an IT service provider based in the Munich area has compromised customer datasets from Netze BW and Stuttgart Netze. The service provider was tasked with installing modern electricity meters in households in Baden-Württemberg, and attackers exploited a vulnerability in its systems to gain access.

According to the companies, the stolen dataset includes complete names, addresses, email addresses, telephone numbers, and serial numbers of the installed meters. Attackers also copied images of the meter units, presumably photographs taken during installation for documentation purposes. According to current knowledge, payment data or bank details were not part of the dataset.

The incident is typical of supply chain attacks: not the network operators themselves, but an external contractor with access to customer data became the attack target. External service providers often operate under less stringent security standards than their clients while simultaneously possessing broad data access. Such indirect attack vectors have been among the most common entry points in the IT security industry for years.

With the stolen data – particularly the combination of names, contact information, and meter numbers – highly convincing fraud attempts can be executed. Realistic scenarios include forged calls or emails that reference the meter replacement that took place, building trust to obtain access credentials or payments.

Netze BW advises affected customers to exercise heightened caution when receiving unexpected contact. The company’s technicians always identify themselves with an official service ID. In case of doubt, customers should verify identity through the network operator’s regular contact channels and contact the police if suspicious.


Source: www.it-daily.net · Published 16 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: