CenterPoint Energy confirms customer data stolen in cyberattack

A major US utility company, CenterPoint Energy, has confirmed that a cyberattack has compromised customer data. According to reports, an attacker claimed to have stolen nearly 7.5 million records, including sensitive information such as names, addresses, account numbers, and partial Social Security numbers.

CenterPoint Energy provides electric and natural gas services to approximately 7 million customers across four states in the US: Indiana, Minnesota, Ohio, and Texas. The company’s systems were allegedly breached through its public API, which lacked essential security measures against automated access. This allowed the attacker to iterate through millions of IDs, stealing sensitive data.

The attacker, using the alias “4d722e4d656f77”, leaked the stolen data online, claiming that CenterPoint Energy ignored their initial messages and treated them as a joke. The company has since confirmed the breach in a filing with the US Securities and Exchange Commission (SEC), stating that an unauthorized third party obtained personal information relating to a portion of its customers through one of its external-facing systems.

CenterPoint Energy has activated its incident-response procedures, hired third-party cybersecurity experts, strengthened protections on its systems, and reported the incident to law enforcement and regulators. While the company claims that its electric and gas services were not impacted by the cyberattack, multiple lawsuits proposing class actions have already been filed in federal courts by law firms representing potentially affected customers.

The breach is particularly concerning due to the sensitive nature of the data stolen, which includes partial Social Security numbers. This information can be used for identity theft and other malicious activities. CenterPoint Energy’s failure to implement robust security measures against automated access on its public API has raised questions about the company’s cybersecurity posture.

As a result of this breach, customers are advised to remain vigilant and monitor their accounts closely for any suspicious activity. It is essential for users to be aware of phishing scams and other tactics that attackers may use to exploit stolen data. In addition, CenterPoint Energy should take immediate action to implement robust security measures on its systems to prevent similar breaches in the future.

In light of this incident, it is crucial for companies to prioritize cybersecurity and invest in robust security measures to protect sensitive customer data. This includes implementing rate limiting, web application firewalls (WAF), and other essential security features to prevent automated access. By doing so, companies can minimize the risk of similar breaches occurring in the future and maintain trust with their customers.


Source: Bleeping Computer — 2026-09-15