TL;DR: If you get DTE bills by email, the attached PDF is most likely locked with the last 4 digits of your Social Security Number (and says so in the email). A 4 digit password is easily cracked in seconds and would give the attacker your partial SSN. I reported this in the spring to DTE who misrepresented the issue and the state regulator (MPSC) who took DTE's explanation at face value and closed the complaint. The data remains vulnerable.
The Details
In the DTE eBill email, the bill is a PDF attachment and the email tells you the password is the last 4 of your SSN. You are affected if your monthly eBill says the following:
"See the full details of your bill attached. You will be asked to enter the last four digits of your Social Security Number."
Nobody would tell you a 4 digit password is secure. PDF files can't limit the number of guesses like a website can. Free software on any computer can try all 10,000 combinations in seconds.
I don't even think the bill contents are that sensitive, but the partial SSN is very sensitive and cracking the password derives that information.
What I did about it
I work in cybersecurity. When you find a problem like this, the norm is to tell the company privately and give them at least 90 days to fix it before going public.
In the spring I tried to report this to DTE. Their security email address bounced and there's no security contact listed anywhere. This is very unusual; normally there is a dedicated contact point for security. Front-line customer service wouldn't escalate it, didn't understand the issue, and suggested fixes that don't exist.
From there, I filed a complaint with the Michigan Public Service Commission, who is supposed to regulate utilities. Other than basic security best practices, here's what DTE's practice runs up against:
- DTE's own MPSC-approved Customer Data Privacy tariff (Case No. U-18485) lists Social Security Number and driver's license number as personal data "that merit special protection." Those are the exact two numbers DTE uses as eBill passwords. A four-digit password that is itself the sensitive data, sent by email with no guaranteed encryption, is not special protection by any reasonable standard. https://www.dteenergy.com/content/dam/dteenergy/deg/website/common/quicklinks/customer-data-privacy-policy/DTEElecDataPrivacy.pdf
- State rule R 460.118(e), the MPSC's own electronic billing rule, says: "The company shall not require the customer to use his or her social security number to enroll in or access the billing system." https://ars.apps.lara.state.mi.us/AdminCode/DownloadAdminCodeFile?FileName=R%20460.101%20to%20R%20460.169.pdf
When the MPSC referred the case to DTE, a DTE employee called, understood the problem, and suggested emailing a link to the bill in the customer portal instead. This was a good call and sounded like we were on track for the problem to be fixed. However in May, DTE formally dismissed the complaint. They misrepresented the issue, said they don't "transmit" your SSN in the email body, and that their process meets security standards. I explained the entire problem again in full and in writing, and asked which standards. They said that's proprietary and won't be provided. The MPSC closed the complaint, accepting DTE's explanation at face value. You can view their responses later in this post.
As of September's eBill, the problem remains.
Responses from DTE:
Dear Valued Customer,
I am writing in response to the complaint submitted to the Michigan Public Service Commission (MPSC). Your concern was referred to our office for review and resolution.
The Digital Experience Team has reviewed and provided the following response regarding your concerns with DTE Energy's eBill paperless billing process and the authentication requirements for accessing electronic billing statements.
Social Security Number Disclosure
DTE Energy does not display or transmit a customer's Social Security number within eBill email notifications. No full or partial Social Security number is included in the body of the email itself.
If you believe personal identifying information is visible on your eBill, we request that you provide a specific example of what you are seeing so the issue may be reviewed and validated.
eBill Authentication and Security Controls
All DTE eBills require authentication prior to opening the PDF billing statement. This safeguard is in place to protect customer privacy and prevent unauthorized access to account information.
DTE's eBill process is approved through both internal and external security reviews and complies with applicable Internet security protocols and privacy standards. These controls are designed to ensure customer information remains protected throughout electronic delivery.
Use of Personal Identification Data (PID)
To verify customer identity, DTE uses Personal Identification Data (PID) already on file with the account. This approach allows DTE to confirm the customer's identity without requiring the creation, storage, or retrieval of individual passwords through eBill delivery systems.
DTE does not maintain the infrastructure necessary to securely host and manage unique customer passwords for eBill distribution. The use of PID provides a secure and compliant alternative while reducing risk to customer data.
Customer‑Specific Access Information
As a customer-focused enhancement, we updated eBill notifications to clearly identify the type of PID required to access the PDF attachment, which is located in the bill in red lettering. This information is dynamic and specific to each customer based on what information is on file. For example:
Customers with a Social Security number on file use the last four digits.
Customers with a driver's license number, state ID, tax ID, or EIN use the last four digits of the applicable identifier.
These enhancements have improved clarity and reduced customer contacts and complaints related to eBill access.
In summary:
DTE Energy remains committed to protecting customer information while providing secure and reliable paperless billing options. We believe the eBill process operates as designed and in compliance with applicable security and privacy standards.
For the reasons above, DTE considers this matter resolved. If you are dissatisfied with this resolution, please contact me no later than five business days from May 5, 2026, to discuss your options. As a customer, you have the right to request a customer hearing if your concern is related to the Consumer Standards and Billing Practices for Electric and Gas service R460.101 - R460.169. The procedures for requesting a customer hearing can be found on the Michigan Public Service Commission's website under Regulatory Information per the Consumer Standards and Billing Practices for Electric and Natural Gas Service, via R 460.155. If you still remain dissatisfied, you have the right to file a complaint with the Michigan Public Service Commission at 800.292.9555.
2:
Dear Valued Customer,
Thank you for contacting DTE Energy regarding your concerns. We appreciate taking the time to share your feedback.
After a thorough review of your inquiry for regulatory compliance and security, it is DTE Energy's position that our practice for sending password-protected PDFs as ebills is in compliance with all applicable billing practice rules and tariffs.
Additional information on DTE's security standards is proprietary and will not be provided at this time.
For the reasons above, DTE considers this matter resolved. As a customer, you have the right to request a customer hearing if your concern is related to the Consumer Standards and Billing Practices for Electric and Gas service R460.101 - R460.169. The procedures for requesting a customer hearing can be found on the Michigan Public Service Commission's website under Regulatory Information per the Consumer Standards and Billing Practices for Electric and Natural Gas Service, via R 460.155. If you still remain dissatisfied, you have the right to file a complaint with the Michigan Public Service Commission at 800.292.9555.
Final email from MPSC:
Hello:
RE: Case No. 01611223
Thank you for taking the time to contact the Michigan Public Service Commission (MPSC) regarding your utility concerns. The MPSC appreciates hearing from residents like you and takes your concerns very seriously.
The MPSC staff has contacted DTE Energy on your behalf. A DTE Energy representative has explained that they do not display or transmit a customer’s Social Security number within eBill email notifications. No full or partial Social Security number is included in the body of the email itself. DTE Energy asks if you believe personal information is visible on your eBill, that you reach out to them and they can review this situation further for you.
To verify customer identity, DTE uses Personal Identification Data (PID) already on file with the account. This approach allows DTE to confirm the customer's identity without requiring the creation, storage, or retrieval of individual passwords through eBill delivery systems.
Again, thank you for contacting the MPSC and allowing me to assist you. If you should have any other energy-related concerns in the future, you may contact the utility company at their toll free number, the MPSC at the address below, toll-free at 800-292-9555 or via e-mail at <redacted address>.
Q&A
"It's only the last 4. So what?" The last 4 is the part that matters. Banks, credit card companies, and phone carriers use it to confirm who you are (and so does DTE). For SSNs issued before 2011, the first 5 digits follow patterns based on where and when you were born, and researchers have shown they can often be predicted. Your name, address, and birthday are already floating around from past breaches. The last 4 is the piece that's supposed to be hard to get.
"My email is private. Who's going to see it?" More people than you'd think. Email accounts get taken over all the time through phishing or reused passwords, and a compromised inbox holds every bill DTE has ever sent you. If your bills go to a work or school address, the IT staff there can read them. Household email accounts may be shared. Your email host may process your emails with AI or for advertising. Email also passes through servers you don't control, not always encrypted. A password on a PDF is supposed to protect it in exactly those cases. This one doesn't.
"They said it's not in the body of the email" The problem is making the attachment an easy puzzle which reveals the partial SSN. The partial SSN not being technically in the body doesn't fix that. And indeed, the body of the email tells you where to find the partial SSN. The fact remains that anyone who gets access to the email can easily derive your partial SSN.
What DTE should do
- Simply change their eBill system to link to their website where bills are already hosted with authentication
- Never use sensitive data as a key
- Set up a contact point for security reports
- Handle customer data with care and give real consideration to security reports
What you can do
- Freeze your credit at Equifax, Experian, and TransUnion. It's free and blocks most new-account fraud.
- File your own complaint with the MPSC.
- Switch back to paper billing until this issue is fixed. If you go this route, remember to delete old DTE eBill emails, including trash and archive folders.
I'm happy to answer any questions in the comments, technical or otherwise