Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen
CenterPoint Energy confirmed a breach after a hacker claimed stealing 7.49 million customer records, including partial Social Security numbers, via an unprotected API.
CenterPoint Energy disclosed in an SEC 8-K filing that an unauthorized third party obtained personal information of a portion of its customers through an external-facing system. A threat actor using the alias '4d722e4d656f77' claimed on a cybercrime forum to have extracted over 7.49 million records, including names, addresses, account numbers, billing data, and partial Social Security numbers, via an API lacking authentication, rate limiting, and WAF protection. The company confirmed the breach but not the record count; energy services were unaffected and the investigation is ongoing.
Healthcare facilities operator Nutex says patient, employee data stolen in August incident
The Gentlemen ransomware gang claims the theft of patient and employee data from healthcare operator Nutex Health, which disclosed the extortion in SEC filings.
Nutex Health said in an 8-K filing that intruders broke into its servers and exfiltrated patient, employee, provider and confidential financial data, and that it is being extorted with threats to publish the information. A Texas class action was filed after the company's August 24 disclosure, and Nutex cannot yet estimate the incident's impact. The Gentlemen ransomware-as-a-service gang, active since September 2025 and believed Russia-based, listed Nutex on its leak site; Dragos ranked it third among groups attacking industrial organizations in Q2 2026 with 125 claimed attacks.
CenterPoint Energy confirms data breach following claims on hacking forum
CenterPoint Energy confirmed a breach after a hacker claimed stealing 7.49 million customer records via an unauthenticated API lacking WAF, rate limiting, and token checks.
CenterPoint Energy, a Houston-based utility serving about 7 million customers, confirmed in a September 14 SEC Form 8-K that an unauthorized third party accessed customer data through an external system after a hacker posted a 7.49 million-line dataset online. The exposed fields include names, phone numbers, addresses, account numbers, emails, driver's license numbers, and the last four digits of Social Security numbers. The hacker said the API had no web application firewall, rate limiting, certificate checks, or authentication token, and that a CAPTCHA stopped exfiltration at 7.49 million of a claimed 17.44 million lines. The company faces multiple class action lawsuits and is working with outside experts to determine scope.
CenterPoint Energy confirms customer data stolen in cyberattack
CenterPoint Energy confirms attackers stole customer personal data, with a threat actor leaking 7.49 million records scraped from an unprotected API.
CenterPoint Energy, a utility serving about 7 million metered customers across Indiana, Minnesota, Ohio, and Texas, confirmed in an SEC filing that an unauthorized third party obtained customer personal information via an external-facing system. A threat actor using the alias "4d722e4d656f77" leaked 7.49 million records containing names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers. The actor claims the data was exfiltrated by iterating through millions of IDs on CenterPoint's public API, which lacked rate limiting and WAF protections. Electric and gas services were not impacted, but multiple federal class-action lawsuits have already been filed.
Electronic health record company says customer data stolen in breach
Veradigm disclosed that attackers used stolen vendor credentials via an API to steal patient data including Social Security numbers, as the Gentlemen ransomware gang claims 3.5 million patients' records.
Electronic health records company Veradigm filed an 8-K with the SEC stating that an unauthorized party obtained credentials from a vendor's environment and used them to access a Veradigm API, downloading patients' personal data including Social Security numbers; no clinical or medical data was involved. The Gentlemen ransomware gang added Veradigm to its leak site, claiming theft of 3.5 million patients' health records. Access was limited to the specific API interface, with no operational disruption. Veradigm was previously hit by SamSam ransomware in 2019 and disclosed a December 2024 breach affecting 2,672,036 people.
Veradigm warns of patient data breach after ransomware gang claims attack
Healthcare vendor Veradigm disclosed a patient data breach via a third-party vendor's credentials, which the Gentlemen ransomware gang claims involved 3.5 million records.
Veradigm, formerly Allscripts, told the SEC that an attacker used compromised credentials from a third-party vendor to access a customer-service API and copy patient data, including personal details and Social Security numbers, without touching clinical data or the broader network. The Gentlemen ransomware group listed Veradigm on its leak site claiming 3.5 million patient records and threatened to publish the data by September 11 unless ransom negotiations start. The gang, active since mid-2025, runs double extortion across Windows, Linux, NAS, BSD and ESXi, lists 800+ victims in 86 countries, and has been linked to a SystemBC proxy botnet and the GentleKiller EDR killer. Veradigm is notifying affected individuals, offering credit monitoring, and says it does not expect a material business impact.