Skip to content
Tech News
← Back to articles

CenterPoint Energy confirms customer data stolen in cyberattack

read original get Aura Identity Theft Protection Subscription → more articles
Why This Matters

CenterPoint Energy, a major U.S. utility serving millions across four states, confirmed a breach after a hacker leaked nearly 7.5 million customer records allegedly stolen due to an unprotected public API. The incident underscores ongoing risks to critical infrastructure providers and highlights how basic security gaps—like missing rate limiting and WAF protections—can expose sensitive personal and financial data at massive scale.

Key Takeaways
Worth a Look

Aura Identity Theft Protection Subscription — With millions of records including partial SSNs exposed in this breach, monitoring your identity for fraudulent use is a smart move. Aura offers identity theft monitoring and alerts that can help you catch misuse of your personal data early after incidents like this one.

See Aura Identity Theft Protection Subscription on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

CenterPoint Energy disclosed a breach compromising some customers’ personal information after an attacker leaked data allegedly stolen from the utility company.

An investigation started after the company discovered an online post from a threat actor claiming to have stolen 7.49 million records.

CenterPoint Energy is a Houston-based public utility company that provides electric and natural gas services and operates power generation facilities.

It serves approximately 7 million metered customers across Indiana, Minnesota, Ohio, and Texas, and employs roughly 8,300 people, generating over $9.3 billion in annual revenue.

Earlier this month, a threat actor using the alias “4d722e4d656f77” told BleepingComputer they stole from CenterPoint Energy 7.49 million customer records that include names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers (SSNs).

The threat actor leaked the data, claiming that the company ignored their messages and treated them as a joke.

According to the intruder, they exfiltrated the data by iterating through millions of IDs on CenterPoint’s public API, which lacked rate limiting, web application firewall (WAF) protection, and other security measures against automated access.

In a filing with the U.S. Securities and Exchange Commission (SEC), CenterPoint Energy confirms that data was stolen, but does not name the threat actor, the number of affected customers, or the types of compromised data.

“While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external-facing systems,” reads the SEC filing.

“The Company is continuing to work with third-party experts to determine the scope of customers and personal information affected by the incident and intends to notify affected customers and regulatory authorities as required by applicable law.”

... continue reading