Cybersecurity

CenterPoint Energy Confirms Customer Data Theft in Cyberattack

CenterPoint Energy confirmed that an unauthorized party obtained personal information belonging to some of its customers through one of its externally exposed systems, after an attacker claimed to have leaked 7.49 million records. The company has not yet determined the number of affected individuals or the types of data stolen, while response procedures have begun and potential class-action lawsuits have emerged.

2026-09-15
3 min read
3 views
فريق تحرير certi.news
CenterPoint Energy Confirms Customer Data Theft in Cyberattack

CenterPoint Energy confirmed that an unauthorized party obtained personal information associated with some of its customers through one of its external-facing systems, after an online post appeared claiming to contain data stolen from the company. The company said in a filing with the U.S. Securities and Exchange Commission (SEC) that the investigation is ongoing, without disclosing the number of affected customers or the nature of the information accessed.

The investigation began after the company detected a post from a threat actor claiming to have stolen 7.49 million records. The attacker, who used the alias 4d722e4d656f77, said the data included names, phone numbers, service and billing addresses, account numbers, billing amounts, and portions of Social Security numbers. The attacker also published the data, claiming that the company had ignored the attacker’s messages and treated them as a joke.

These details, including the size of the leak and the types of data, have not yet been independently confirmed by CenterPoint Energy. The company confirmed only that a third party obtained personal information through an externally exposed system, and said it is working with outside experts to determine the scope of the incident and the affected data and customers before notifying customers and regulators as required by law.

What Is Known About the Access Method?

According to the attacker’s account reported by BleepingComputer, the data was extracted by trying millions of identifiers through a public application programming interface operated by the company. The attacker claimed that the interface lacked request-rate limiting, web application firewall (WAF) protection, and other measures restricting automated access. This account still requires confirmation from the official investigation, but it suggests that internet-accessible systems can become a broad entry point if their query and monitoring mechanisms are not restricted.

Services Continue, but the Impact of the Incident Remains Undetermined

CenterPoint Energy said that electricity and gas services were not affected and that it does not currently expect a material impact on its operations or financial position. The company operates electricity and natural gas services and power-generation facilities, serving approximately 7 million metered customers in Indiana, Minnesota, Ohio, and Texas, with a workforce of approximately 8,300 employees and annual revenue exceeding $9.3 billion.

The company activated its incident-response procedures, engaged external cybersecurity experts, strengthened the protection of its systems, and notified law-enforcement and regulatory authorities. In parallel, several proposed class-action lawsuits were filed in federal courts, and the law firms representing potentially affected customers allege that the breach occurred between August 17 and September 1.

Why Does This News Matter?

The significance of the incident lies in the combination of the sensitivity of customer data and the scale of the figure cited by the attacker, while key details remain officially unresolved. The fact that electricity and gas services were not affected does not eliminate the risk of misuse of account and billing data, but it means that the incident disclosed so far concerns data confidentiality more than service continuity. The investigation’s findings will determine the number of people actually affected, whether the leaked data includes Social Security numbers or other information, and the extent to which customer notification or additional protective measures will be necessary.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news