ZeroHour
Story · 5 sources · 5 articlesfirst updated ()

CenterPoint Energy confirms customer data breach after threat actor leaks 7.49 million records scraped from internet-facing API

highData breachexploited in the wildimportance 78
What's new: Updated after new reporting: CenterPoint said cybersecurity insurance is expected to offset incident response and notification costs; clarified the compromised system was an internet-facing customer system rather than operational technology or grid management; and the company warned the number of affected individuals and exposed data types could grow as the forensic review continues.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

CenterPoint Energy confirmed in a September 14, 2026 SEC Form 8-K that an unauthorized third party obtained customer personal data through an internet-facing customer system, after a threat actor leaked a 7.49 million-record dataset allegedly scraped from an…

CenterPoint Energy, a Houston-based utility serving about 7 million metered customers across Indiana, Minnesota, Ohio, and Texas, confirmed in a September 14, 2026 SEC Form 8-K that an unauthorized third party obtained personal information of a portion of its customers through an external, internet-facing system — not operational technology or grid management. The company learned of the incident after an online post claimed possession of a customer dataset, then activated incident-response protocols, engaged external forensic specialists, and notified law enforcement and certain regulators. A threat actor using the alias '4d722e4d656f77' posted a 7.49 million-record dataset online (advertised as a 2.5 GB archive), saying the data was exfiltrated by iterating through millions of IDs on CenterPoint's public API, which reportedly lacked a web application firewall, rate limiting, JWT authentication tokens, and certificate checks; a CAPTCHA allegedly stopped exfiltration at 7.49 million of a claimed 17.44 million accessible lines, with data pulled in JSONL then converted to CSV. Leaked fields reportedly include names, phone numbers, service and billing addresses, account numbers, billing amounts, emails, driver's license numbers, and the last four digits of Social Security numbers. CenterPoint has not officially confirmed a record count or data types and warned the scope could grow as the review continues. Electric and gas delivery operations were unaffected; the company does not expect a material financial impact, though response, notification, and compliance costs are being incurred, with cybersecurity insurance expected to offset incident-response and notification costs. Customer and regulator notifications are pending the investigation, amid expected phishing and credential-stuffing risk. Multiple federal class-action lawsuits have already been filed by customers across several states, alleging the breach occurred between August 17 and September 1.

  • CenterPoint Energy (Houston-based, ~7 million metered customers in Indiana, Minnesota, Ohio, and Texas) disclosed the breach in a Form 8-K filed September 14, 2026.
  • An unauthorized third party accessed personal data of a portion of customers via an external, internet-facing customer system; operational technology and grid management were not affected.
  • CenterPoint learned of the incident after an online post claimed possession of a customer dataset, then engaged external forensic specialists and notified law enforcement and certain regulators.
  • Threat actor alias '4d722e4d656f77' leaked a 7.49 million-record dataset advertised as a 2.5 GB archive and claims 17.44 million records were accessible (unverified).
  • Data was allegedly exfiltrated by iterating through millions of IDs on a public API lacking WAF protection, rate limiting, JWT authentication tokens, and certificate checks; a CAPTCHA halted exfiltration at 7.49 million lines, with data…
  • Reportedly exposed fields include names, phone numbers, service and billing addresses, account numbers, billing amounts, emails, driver's license numbers, and the last four digits of Social Security numbers.
  • CenterPoint confirmed the breach but not the record count or data types; the number of affected individuals remains under investigation and the company warned the scope could grow.
  • Electric and gas delivery operations were unaffected; no material financial impact is expected, though response, notification, and compliance costs are being incurred.

Coverage timeline

  1. · 1d ago
    BleepingComputer· 78
    CenterPoint Energy confirms customer data stolen in cyberattack

    CenterPoint Energy confirms attackers stole customer personal data, with a threat actor leaking 7.49 million records scraped from an unprotected API.

  2. · 19h ago
    Security Affairs· 78
    Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen

    CenterPoint Energy confirmed a breach after a hacker claimed stealing 7.49 million customer records, including partial Social Security numbers, via an unprotected API.

  3. · 17h ago
    Help Net Security· 72
    CenterPoint Energy confirms data breach following claims on hacking forum

    CenterPoint Energy confirmed a breach after a hacker claimed stealing 7.49 million customer records via an unauthenticated API lacking WAF, rate limiting, and token checks.

  4. · 16h ago
    GBHackers· 70
    CenterPoint Energy Confirms Data Breach Exposing Customers’ Personal Information

    CenterPoint Energy confirmed an unauthorized third party accessed customer personal data via an external system, disclosed in an SEC Form 8-K filing.

  5. · 12h ago
    Cyber Security News· 70
    CenterPoint Energy Data Breach – Hackers Stolen Customer’s Personal Data

    CenterPoint Energy confirmed via SEC 8-K filing that an unauthorized third party stole customer personal data from an internet-facing system.