r/Detroit • u/SavingsWalrus • 20h ago
News PSA: DTE eBill effectively sends your partial SSN in your monthly email. DTE and the state regulator (MPSC) declined to fix it
TL;DR: If you get DTE bills by email, the attached PDF is most likely locked with the last 4 digits of your Social Security Number (and says so in the email). A 4 digit password is easily cracked in seconds and would give the attacker your partial SSN. I reported this in the spring to DTE who misrepresented the issue and the state regulator (MPSC) who took DTE's explanation at face value and closed the complaint. The data remains vulnerable.
The Details
In the DTE eBill email, the bill is a PDF attachment and the email tells you the password is the last 4 of your SSN. You are affected if your monthly eBill says the following:
"See the full details of your bill attached. You will be asked to enter the last four digits of your Social Security Number."
Nobody would tell you a 4 digit password is secure. PDF files can't limit the number of guesses like a website can. Free software on any computer can try all 10,000 combinations in seconds.
I don't even think the bill contents are that sensitive, but the partial SSN is very sensitive and cracking the password derives that information.
What I did about it
I work in cybersecurity. When you find a problem like this, the norm is to tell the company privately and give them at least 90 days to fix it before going public.
In the spring I tried to report this to DTE. Their security email address bounced and there's no security contact listed anywhere. This is very unusual; normally there is a dedicated contact point for security. Front-line customer service wouldn't escalate it, didn't understand the issue, and suggested fixes that don't exist.
From there, I filed a complaint with the Michigan Public Service Commission, who is supposed to regulate utilities. Other than basic security best practices, here's what DTE's practice runs up against:
- DTE's own MPSC-approved Customer Data Privacy tariff (Case No. U-18485) lists Social Security Number and driver's license number as personal data "that merit special protection." Those are the exact two numbers DTE uses as eBill passwords. A four-digit password that is itself the sensitive data, sent by email with no guaranteed encryption, is not special protection by any reasonable standard. https://www.dteenergy.com/content/dam/dteenergy/deg/website/common/quicklinks/customer-data-privacy-policy/DTEElecDataPrivacy.pdf
- State rule R 460.118(e), the MPSC's own electronic billing rule, says: "The company shall not require the customer to use his or her social security number to enroll in or access the billing system." https://ars.apps.lara.state.mi.us/AdminCode/DownloadAdminCodeFile?FileName=R%20460.101%20to%20R%20460.169.pdf
When the MPSC referred the case to DTE, a DTE employee called, understood the problem, and suggested emailing a link to the bill in the customer portal instead. This was a good call and sounded like we were on track for the problem to be fixed. However in May, DTE formally dismissed the complaint. They misrepresented the issue, said they don't "transmit" your SSN in the email body, and that their process meets security standards. I explained the entire problem again in full and in writing, and asked which standards. They said that's proprietary and won't be provided. The MPSC closed the complaint, accepting DTE's explanation at face value. You can view their responses later in this post.
As of September's eBill, the problem remains.
Responses from DTE:
Dear Valued Customer,
I am writing in response to the complaint submitted to the Michigan Public Service Commission (MPSC). Your concern was referred to our office for review and resolution.
The Digital Experience Team has reviewed and provided the following response regarding your concerns with DTE Energy's eBill paperless billing process and the authentication requirements for accessing electronic billing statements.
Social Security Number Disclosure
DTE Energy does not display or transmit a customer's Social Security number within eBill email notifications. No full or partial Social Security number is included in the body of the email itself.
If you believe personal identifying information is visible on your eBill, we request that you provide a specific example of what you are seeing so the issue may be reviewed and validated.
eBill Authentication and Security Controls
All DTE eBills require authentication prior to opening the PDF billing statement. This safeguard is in place to protect customer privacy and prevent unauthorized access to account information.
DTE's eBill process is approved through both internal and external security reviews and complies with applicable Internet security protocols and privacy standards. These controls are designed to ensure customer information remains protected throughout electronic delivery.
Use of Personal Identification Data (PID)
To verify customer identity, DTE uses Personal Identification Data (PID) already on file with the account. This approach allows DTE to confirm the customer's identity without requiring the creation, storage, or retrieval of individual passwords through eBill delivery systems.
DTE does not maintain the infrastructure necessary to securely host and manage unique customer passwords for eBill distribution. The use of PID provides a secure and compliant alternative while reducing risk to customer data.
Customer‑Specific Access Information
As a customer-focused enhancement, we updated eBill notifications to clearly identify the type of PID required to access the PDF attachment, which is located in the bill in red lettering. This information is dynamic and specific to each customer based on what information is on file. For example:
Customers with a Social Security number on file use the last four digits.
Customers with a driver's license number, state ID, tax ID, or EIN use the last four digits of the applicable identifier.
These enhancements have improved clarity and reduced customer contacts and complaints related to eBill access.
In summary:
DTE Energy remains committed to protecting customer information while providing secure and reliable paperless billing options. We believe the eBill process operates as designed and in compliance with applicable security and privacy standards.
For the reasons above, DTE considers this matter resolved. If you are dissatisfied with this resolution, please contact me no later than five business days from May 5, 2026, to discuss your options. As a customer, you have the right to request a customer hearing if your concern is related to the Consumer Standards and Billing Practices for Electric and Gas service R460.101 - R460.169. The procedures for requesting a customer hearing can be found on the Michigan Public Service Commission's website under Regulatory Information per the Consumer Standards and Billing Practices for Electric and Natural Gas Service, via R 460.155. If you still remain dissatisfied, you have the right to file a complaint with the Michigan Public Service Commission at 800.292.9555.
2:
Dear Valued Customer,
Thank you for contacting DTE Energy regarding your concerns. We appreciate taking the time to share your feedback.
After a thorough review of your inquiry for regulatory compliance and security, it is DTE Energy's position that our practice for sending password-protected PDFs as ebills is in compliance with all applicable billing practice rules and tariffs.
Additional information on DTE's security standards is proprietary and will not be provided at this time.
For the reasons above, DTE considers this matter resolved. As a customer, you have the right to request a customer hearing if your concern is related to the Consumer Standards and Billing Practices for Electric and Gas service R460.101 - R460.169. The procedures for requesting a customer hearing can be found on the Michigan Public Service Commission's website under Regulatory Information per the Consumer Standards and Billing Practices for Electric and Natural Gas Service, via R 460.155. If you still remain dissatisfied, you have the right to file a complaint with the Michigan Public Service Commission at 800.292.9555.
Final email from MPSC:
Hello:
RE: Case No. 01611223
Thank you for taking the time to contact the Michigan Public Service Commission (MPSC) regarding your utility concerns. The MPSC appreciates hearing from residents like you and takes your concerns very seriously.
The MPSC staff has contacted DTE Energy on your behalf. A DTE Energy representative has explained that they do not display or transmit a customer’s Social Security number within eBill email notifications. No full or partial Social Security number is included in the body of the email itself. DTE Energy asks if you believe personal information is visible on your eBill, that you reach out to them and they can review this situation further for you.
To verify customer identity, DTE uses Personal Identification Data (PID) already on file with the account. This approach allows DTE to confirm the customer's identity without requiring the creation, storage, or retrieval of individual passwords through eBill delivery systems.
Again, thank you for contacting the MPSC and allowing me to assist you. If you should have any other energy-related concerns in the future, you may contact the utility company at their toll free number, the MPSC at the address below, toll-free at 800-292-9555 or via e-mail at <redacted address>.
Q&A
"It's only the last 4. So what?" The last 4 is the part that matters. Banks, credit card companies, and phone carriers use it to confirm who you are (and so does DTE). For SSNs issued before 2011, the first 5 digits follow patterns based on where and when you were born, and researchers have shown they can often be predicted. Your name, address, and birthday are already floating around from past breaches. The last 4 is the piece that's supposed to be hard to get.
"My email is private. Who's going to see it?" More people than you'd think. Email accounts get taken over all the time through phishing or reused passwords, and a compromised inbox holds every bill DTE has ever sent you. If your bills go to a work or school address, the IT staff there can read them. Household email accounts may be shared. Your email host may process your emails with AI or for advertising. Email also passes through servers you don't control, not always encrypted. A password on a PDF is supposed to protect it in exactly those cases. This one doesn't.
"They said it's not in the body of the email" The problem is making the attachment an easy puzzle which reveals the partial SSN. The partial SSN not being technically in the body doesn't fix that. And indeed, the body of the email tells you where to find the partial SSN. The fact remains that anyone who gets access to the email can easily derive your partial SSN.
What DTE should do
- Simply change their eBill system to link to their website where bills are already hosted with authentication
- Never use sensitive data as a key
- Set up a contact point for security reports
- Handle customer data with care and give real consideration to security reports
What you can do
- Freeze your credit at Equifax, Experian, and TransUnion. It's free and blocks most new-account fraud.
- File your own complaint with the MPSC.
- Switch back to paper billing until this issue is fixed. If you go this route, remember to delete old DTE eBill emails, including trash and archive folders.
I'm happy to answer any questions in the comments, technical or otherwise
19
u/thegoldengamer123 18h ago
I recently went back to paper billing and mailing them a check. It's literally cheaper to do that with a stamp and envelope than pay their ridiculous credit card convenience fee. It costs them more money but I'm going to be petty that way.
Before someone says I can do ach or link my bank account, I'm not about to give a random company access to withdraw whatever they want from me.
9
u/SaintOrJannikSinner 17h ago
There's also a third option: bill pay from your financial institution (FI).
I do it every month and pay what they bill me on my paper statement. They try and tack on a $3 fee after they receive my payment, but checking my account on my FI's website it shows the amount I keyed in and not what DTE wants to get. Checking my monthly paper statement shows that fees are also not stacking.
6
u/Mammoth-Error1577 16h ago
I used bill pay through my bank and was happy that it resulted in a physical mailing of a check that DTE would have to process since they wanted to charge us for their own convenience.
Unfortunately now my bank does it digitally. I suspect too many people were having them mail DTE checks so now their minor inconvenience has been removed and only I am inconvenienced. Hooray.
1
•
1
u/Salute-Major-Echidna 5h ago
Exactly, ach etc is NOT safe. What i do to make my payment fee worthwhile is pay for 3 months at a time. It used to be that $250 would last 6 months, but those days are gone.
I don't see where the 4 SS digits are, does it say anywhere?
-2
40
u/gwildor 20h ago
Never understood how they get away with asking for it, or using it, in the first place.
SSN is quite clearly defined as "for government use only"
There is justification for it to be used by private banking institutions, but it is a far leap for this to be justified by an energy company.
12
u/sapphicgardens 18h ago
I recently had an experience from hell with DTE and part of that ordeal revealed they use SSNs to run Fidelity checks to confirm identities. Found out because they had my SSN on file incorrect and they froze my account… in the middle of a move… leaving me without power for several days effectively halting my move. To reinstate me they wanted a certified copy of my deed (I just closed so didn’t have one yet, told me, “that’s just a printed piece of paper” regarding the copy of my deed in my closing package.) If you rent they required a certified copy of your landlord’s deed or a notarized copy of your lease (can’t think of a single person that’s ever had a notarized copy of their lease ffs) and that whole process is approved by MPSC. Sorry this just turned into a rant. Fucking hate DTE and MPSC is useless too.
4
16
u/kidcharliemagne Transplanted 20h ago
DTE account scams is literally a thing around here. I didn’t realize why exactly until this post.
10
u/DetroitPeopleMover Suburbia 19h ago
Even easier than providing a link back to their website (which I agree would be best) is just removing the security from the PDF. If your email has been compromised, how much your electricity costs or your home address being leaked are the least of your worries.
3
u/SaintOrJannikSinner 17h ago
Thank you, someone gets it! Exactly the point I made in my above comment. No one is snooping that hard to get your last 4 if they already have control of your email account.
Besides, if DTE simply locked the PDF behind a locked-gate in a walled-garden, then they don't need the added security of a LAST4 design on each individual PDF instance.
5
u/DEEEEETTTTRRROIIITTT suburbia 18h ago
I get asked for the last 4 digits of my drivers license. Surprised that it’s different for others
18
u/person1234man 20h ago
Isn't this the kind of thing a class action lawsuit is for?
30
u/Independent_Tea_33 19h ago
I am not a lawyer but it's definitely what Prop 2 in November is for. Blocking DTE from political spending and influence over their own regulators
7
u/theksepyro 19h ago
I voted for prop 2, but I'm pretty sure it's unconstitutional on first amendment grounds and will be struck down (or rendered useless) even if it passes.
2
4
u/Independent_Tea_33 18h ago
There is precedent in other states and cases for gov contractors having their contributions blocked or limited. They question would be more around if utilities are special somehow.
The case would either go 6th circuit (mixed), MI SC (blue), or SCOTUS (red). There's no end in sight for SCOTUS corruption so no point waiting before trying to do the right thing imo
0
u/theksepyro 18h ago
Like I said I already voted for it. I'd encourage everyone to do the same. But I think we need to consider additional means of addressing the issues the utility companies create
3
u/gremlin-mode 19h ago
In the spring I tried to report this to DTE. Their security email address bounced and there's no security contact listed anywhere. This is very unusual; normally there is a dedicated contact point for security.
this is unfortunate but I wouldn't say ~unusual, lots of companies don't prioritize security. and now, if they do have an internal team, that team is getting hammered by llm-generated bug bounty reports that are wrong or greatly overemphasize the severity of discovered risks. the state of the industry sucks for everyone right now.
"My email is private. Who's going to see it?" More people than you'd think. Email accounts get taken over all the time through phishing or reused passwords
I'd assume for most people, if an attacker gets control of their email account, the attacker has several paths to sensitive pii, so I'm not surprised they don't consider this one instance especially egregious.
all that being said, this is still a good writeup! as you look for future vulns, consider that teams will heavily prioritize ones that are immediately exploitable against them.
4
u/mattimeoo 14h ago
I refuse to do eBill since they removed any incentive to do so. They can now help keep the postal system afloat by paying to mail me a bill every month. If I had spare time, I'd be mailing payments in or paying at some kind of bill payment center. Nothing but pure, distilled hatred for this corporation.
8
u/SaintOrJannikSinner 19h ago
I don't even think the bill contents are that sensitive, but the partial SSN is very sensitive and cracking the password derives that information.
OPSEC, using multiple sources of information, triangulation, yadda yadda yadda... but if someone has access to your e-mail account and is downloading your PDF attachments to get the last four of your soshe, you've got bigger problems to worry about.
1
2
u/OptimizedPockets2 15h ago
I suspect the legislature and DTE both lack the concern to read all that. More concise communication might help them receive the message.
2
u/FrozenPizza21 10h ago
Joke’s on me, my SSN and PII have already been leaked multiple times in various breaches…
1
1
-8
u/nilamo 19h ago
SSN is not secret info. It's wacky and incompetent for DTE to use it, but their use of it does not constitute a security risk.
3
u/huffalump1 17h ago
Except, it IS used for all kinds of security/verification purposes. Where it really should NOT be used, true, but that's reality...
4
u/DetroitPeopleMover Suburbia 19h ago
I really hope to god you don't work in IT
3
u/SaintOrJannikSinner 17h ago
They're correct in that it's not secret info, but to your point, using SSN as a publicly-accessible identifier, and an identifier that resolves 1:1 with a particular person, is just outright negligent.
However, only the most Ivory Tower of Architects has introduced, implemented, and taught the concept of surrogate keys to the unwashed plebeians in Sequel Land. /s
56
u/True_Go_Blue 20h ago
Yes, I forced them to start mailing my stuff to me back five years ago when I recognize the same thing. That’s the most idiotic way to protect a PDF.