UK energy company Npower suffered a data security breach after which it permanently closed its mobile app due to sensitive information data leaks from customers.
The attackers used a ‘credential stuffing’ type attack to access customer accounts using login data stolen from another website and targeted its mobile app activity.
Npower even informed all the affected customers & advised them to change their passwords as soon as possible.
"id": "NPO2241622",
"linkid": "npower-",
"type": "Breach",
"date": "02/2021",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"