5 minBusiness
CenterPoint Energy Confirms Customer Data Breach as Hacker Claims 7.49 Million Records
CenterPoint Energy has confirmed that an unauthorized third party obtained personal information belonging to some customers through an external-facing system. A hacker claims to have stolen 7.49 million records, but the company has not verified that figure or the specific data types. The utility says services continue normally and it does not expect a material financial impact.
CenterPoint Energy has confirmed that an unauthorized third party obtained personal information belonging to some of its customers through an external-facing system, the Houston-based utility disclosed in a Sept. 14 filing with the U.S. Securities and Exchange Commission. The company has not publicly stated how many customers were affected or which types of personal information were taken.
The disclosure followed the company's discovery of an online post from a third party claiming to possess a data set containing CenterPoint customer information. CenterPoint activated its cybersecurity incident response procedures and brought in outside cybersecurity experts. As the investigation progressed, the company determined that an unauthorized third party had obtained personal information belonging to some customers through one of its external-facing systems.
A threat actor using the alias «4d722e4d656f77» told BleepingComputer that they obtained 7.49 million CenterPoint customer records. According to the hacker, those records contain addresses, account numbers, billing information and partial Social Security numbers. The attacker later leaked the data after claiming CenterPoint ignored their attempts to make contact.
CenterPoint has confirmed that customer information was stolen, but it has not independently confirmed the 7.49 million record count or the specific list of exposed data. The company also noted that 7.49 million records does not necessarily mean 7.49 million individual people were affected, since one person or household can appear in more than one record. CenterPoint says it is still working to determine the actual scope of the incident.
The attacker's explanation of how the theft allegedly happened may be one of the most significant parts of the breach. The hacker told BleepingComputer they accessed the information by repeatedly cycling through millions of IDs using a public CenterPoint API. An API allows different software systems to exchange information, and companies use them constantly behind websites and apps. According to the attacker, CenterPoint's API lacked protections that could have slowed or blocked mass automated requests. The hacker specifically claimed there was no effective rate limiting or web application firewall protection against the activity.
CenterPoint's SEC filing does not confirm that attack method. What CenterPoint does confirm is that the unauthorized third party obtained information through an external-facing system. That means the API explanation should be treated as the attacker's account until the company or investigators provide more technical details.
CenterPoint says its electric and natural gas services continued operating normally during the incident. The company also says it currently does not expect the breach to have a material impact on its financial condition. CenterPoint plans to notify affected customers and regulators as required once it determines the scope of the incident.
CyberGuy reached out to CenterPoint Energy asking whether it could confirm the hacker's claim that 7.49 million records were stolen, what customer information was affected and whether a public API was involved. CenterPoint referred to its SEC filing and provided this statement: «Our filing speaks for itself.» The company did not provide additional details in response to those questions.
A utility account may not seem as sensitive as a bank account, but it can hold exactly the kind of information a scammer wants before contacting a customer. Someone calling could know a name, a service address, an account number or a recent billing amount, then claim there is a problem with payment. That conversation can feel much more legitimate because the scammer already has information a customer would expect only the utility company to know.
Criminals can also combine information from one breach with details leaked elsewhere. A partial Social Security number, phone number or address may become more useful when paired with another stolen data set. For CenterPoint customers, the key unknowns remain the true number of affected individuals and the exact types of personal information involved. The company has not provided a timeline for when those details will be determined or when notifications will be sent.
6
