CenterPoint Energy confirms customer data stolen in cyberattack

CenterPoint Energy, a major US utility company, has confirmed that customer data was stolen in a cyberattack. The incident, which was disclosed after an attacker leaked the compromised information online, is believed to have affected millions of customers across four states.

The breach, which was uncovered after a threat actor claimed to have stolen 7.49 million records from CenterPoint Energy’s systems, includes sensitive customer data such as names, phone numbers, addresses, account numbers, and partial Social Security numbers. The company has not yet revealed the exact number of affected customers or the types of data that were compromised.

According to an investigation by BleepingComputer, the attacker used a clever technique to exfiltrate the data from CenterPoint Energy’s public API (Application Programming Interface). The API, which is designed to provide authorized access to customer information, lacked critical security measures such as rate limiting and web application firewall protection. This allowed the attacker to iterate through millions of IDs, making it easier for them to steal the sensitive data.

CenterPoint Energy has confirmed that an unauthorized third party obtained personal information from its external-facing systems, but it has not named the threat actor or provided details on the scope of the breach. The company is working with third-party experts to determine the extent of the damage and will notify affected customers and regulatory authorities as required by law.

In a filing with the US Securities and Exchange Commission (SEC), CenterPoint Energy downplayed the impact of the cyberattack, stating that its electric and gas services were not impacted and that the incident is unlikely to affect its business or financial condition. However, multiple lawsuits have already been filed against the company on behalf of potentially affected customers, alleging that the data breach occurred between August 17 and September 1.

The CenterPoint Energy breach highlights the importance of robust security measures in protecting sensitive customer data. Utility companies like CenterPoint Energy rely heavily on public APIs to provide authorized access to customer information, but these APIs can be vulnerable to attack if not properly secured. This incident serves as a reminder that even seemingly secure systems can be compromised by determined attackers.

As a consumer, it’s essential to stay vigilant and monitor your credit reports for any suspicious activity. If you’re a CenterPoint Energy customer, keep an eye on your account statements and credit cards for any unusual transactions. You may also want to consider taking proactive steps to protect your personal data, such as enabling two-factor authentication on your online accounts and using a reputable password manager.

In the face of increasingly sophisticated cyber threats, it’s crucial that companies prioritize robust security measures to safeguard customer data. By doing so, they can mitigate the risk of costly breaches and maintain the trust of their customers.


Source: Bleeping Computer — 2026-09-15