CenterPoint Energy has confirmed that an attacker stole personal information belonging to some of its customers. The utility company launched an investigation after a threat actor claimed to possess 7.49 million customer records.
However, CenterPoint has not confirmed how many people the breach affected or exactly what information the attacker accessed.
Utility Confirms Theft of Customer Information
CenterPoint Energy disclosed the incident in a filing with the US Securities and Exchange Commission.
According to the filing, an unauthorised third party obtained personal information linked to some customers through an external-facing system.
The investigation remains in progress. Therefore, CenterPoint has not yet determined the number of affected customers or the complete range of exposed information.
The company intends to notify customers and regulators as required by applicable laws.
Hacker Claims to Have Stolen 7.49 Million Records
CenterPoint began investigating after discovering an online post from a threat actor who claimed to have stolen 7.49 million customer records.
The attacker uses the alias “4d722e4d656f77” and later published data allegedly taken from the utility. The hacker claimed that CenterPoint had ignored earlier messages and failed to take the threat seriously.
According to the attacker, the stolen records contain customer names, phone numbers and account numbers. The dataset allegedly includes service addresses, billing addresses and payment amounts.
The hacker also claimed that some records contain partial Social Security numbers. However, CenterPoint has not publicly confirmed these details.
Attacker Blames Weak Public API Protections
The threat actor said they extracted the information through a public CenterPoint API. According to the claim, the attacker cycled through millions of identification numbers to retrieve customer records.
The hacker alleged that the API lacked rate limiting and web application firewall protection. These safeguards can detect or slow automated requests that collect large amounts of information.
CenterPoint has not confirmed the attacker’s description of the intrusion method. Its SEC filing only states that the compromise involved an external-facing system.
Therefore, the precise cause of the CenterPoint data breach remains unclear.
Electric and Gas Services Remain Operational
CenterPoint said the incident did not disrupt its electricity or natural gas services. The company also does not expect the breach to have a material effect on its business or financial condition.
The Houston-based utility provides electricity and natural gas services across Indiana, Minnesota, Ohio and Texas. It serves approximately seven million metered customers.
CenterPoint also operates power generation facilities and employs around 8,300 people. The company generates more than $9.3 billion in annual revenue.
The size of its customer base makes any theft of personal information particularly significant. Even if the attacker’s figures prove inaccurate, the confirmed breach could still affect many customers.
CenterPoint Activates Incident Response
The company has activated its incident-response procedures and hired third-party cybersecurity specialists.
CenterPoint said it strengthened protections across its systems after discovering the breach. It also reported the incident to law enforcement agencies and regulators.
Investigators are now working to identify the affected customers and determine what information the attacker obtained.
Once CenterPoint completes that assessment, it will send notifications where required. These notices should provide customers with more specific details about their exposure.
Proposed Class-Action Lawsuits Filed
Several law firms have already filed lawsuits seeking class-action status on behalf of potentially affected customers.
The complaints reportedly allege that the breach occurred between August 17 and September 1. However, the courts have not yet ruled on the claims.
The lawsuits may develop as CenterPoint releases more information about the scale and cause of the incident.
Customers Should Watch for Fraud Attempts
Potentially affected customers should remain cautious about unsolicited calls, emails and text messages that claim to come from CenterPoint.
Stolen names, phone numbers, addresses and account details can make phishing attempts appear convincing. Criminals may use the information to impersonate utility employees or demand fraudulent payments.
Customers should verify unexpected requests through CenterPoint’s official contact channels. They should never share passwords, payment information or authentication codes with unsolicited callers.
Anyone concerned about possible Social Security number exposure should also monitor credit reports and financial accounts for suspicious activity.
CenterPoint has not announced whether it will offer identity protection services. Affected customers should follow future company notifications for additional guidance.


0 responses to “CenterPoint Energy Confirms Customer Data Stolen in Cyberattack”