ZeroHour
Security Affairspublished ()ingested Pierluigi Paganini
Part of a story covered by 2 sources: “CenterPoint Energy confirms customer data breach; threat actor leaks 7.49 million records via unprotected API” — merged summary and timeline →

Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen

highData breach exploited in the wildimportance 78
AI summary · glm-5.3-flash

CenterPoint Energy confirmed a breach after a hacker claimed stealing 7.49 million customer records, including partial Social Security numbers, via an unprotected API.

CenterPoint Energy disclosed in an SEC 8-K filing that an unauthorized third party obtained personal information of a portion of its customers through an external-facing system. A threat actor using the alias '4d722e4d656f77' claimed on a cybercrime forum to have extracted over 7.49 million records, including names, addresses, account numbers, billing data, and partial Social Security numbers, via an API lacking authentication, rate limiting, and WAF protection. The company confirmed the breach but not the record count; energy services were unaffected and the investigation is ongoing.

  • Hacker alias 4d722e4d656f77 advertised a 2.5 GB archive and claims 17.44 million records were accessible.
  • Claimed stolen fields include names, addresses, account numbers, billing amounts, and partial SSNs.
  • Attacker said the API lacked WAF, rate limiting, and JWT authentication; services unaffected.
  • Company will notify customers and regulators; phishing and credential-stuffing risk expected.
Threat actors4d722e4d656f77
OrganizationsCenterPoint Energy
CountriesUnited States
Full article650 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 16, 2026

CenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information.

CenterPoint Energy admitted on Monday that an intruder stole personal information belonging to some of its customers. The Houston-based utility, which supplies electricity and gas to about 7 million accounts across Texas, Indiana, Minnesota and Ohio, disclosed the breach in an SEC filing after a hacker started advertising the data online.

“In September 2026, CenterPoint Energy, Inc. (the “Company”) became aware of an online post by a third party claiming to have obtained a data set containing certain of the Company’s customer information.” reads the FORM 8-K report filed with SEC.”While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external facing systems (the “Incident”).”

CenterPoint said its energy services were not affected. The company is investigating the breach, assessing exposed data, and will notify affected customers, regulators and law enforcement as required.

The company locked down its systems after seeing a post on a dark web forum where a hacker leaked data allegedly stolen from its systems.

On September 12, a threat actor using the alias “4d722e4d656f77” claimed on a cybercrime forum to have extracted roughly 7.49 million customer records from CenterPoint Energy.

“We’ve obtained well over 7.49 Million, each single one line which converts to 7 files in total of (.jsonl) format, which upholds per line 1 user, and we’ve obtained well over 7.49 million lines. As for the (CSV), we’ve filtered long text from (Jsonl), so the CSV will uphold the full PII (personal identity information).” the hacker claimed in the post. “It’s quite funny to think a $26.2 billion company has WEAK protection. We obtained said data from an API they managed and controlled, which lacked proper WAF protection, rate limiting, certification protection, and no JWT/Auth token to pull said data. Mid the 7.49 million mark, they did an attempt to stop us dumping data, which, with a simple CAPTCHA key, in terms, we would have pulled 17.44 million data from said company.”

The hacker claimed the theft of names, phone numbers, service and billing addresses, account numbers, billing amounts, payment status and partial Social Security numbers. He offered a 2.5 GB archive for download. The attacker warned that “next time we won’t simply pull data, we’ll start attacking the main infrastructure,” a line that reads well on a forum but should still be taken seriously by any critical infrastructure operator.

The attackers claim they stole over 7.49 million records through an API they say lacked proper WAF protection, rate limiting and authentication. They also claim the company tried to stop the data dump only after millions of records had been extracted.

CenterPoint’s SEC filing does not name the threat actor, confirm the 7.49 million figure or detail exactly which fields were exposed. It only states that an unauthorized third party obtained personal information “relating to a portion of the Company’s customers through one of the Company’s external-facing systems.” Independent outlets have not been able to fully validate the leaked dataset, and attackers often inflate numbers or repackage old data, so the final scope may differ from the claims.

For now, the takeaway is simple. If you are a CenterPoint customer, assume that your name, address, account details and at least part of your Social Security number may have been exposed. Be careful with targeted phishing, credential-stuffing attacks and fake billing messages that use this information to look legitimate.

The same risk applies across the sector. Internet-facing systems, weak API security and misconfigured services can give attackers an easy way in, while companies may struggle to detect and stop the attack before data is stolen.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/199170/data-breach/texas-utility-centerpoint-energy-confirms-data-breach-after-hacker-claims-7-49m-records-stolen.html