
CenterPoint Energy, the Houston-based utility serving roughly 7 million customers across Indiana, Minnesota, Ohio, and Texas, has confirmed that an attacker stole personal information from its systems after a threat actor publicly leaked what they claim are 7.49 million customer records.
The intruder, going by the alias “4d722e4d656f77,” told BleepingComputer they harvested the data by iterating through millions of customer IDs on CenterPoint’s public API, which lacked rate limiting, web application firewall protection, and other safeguards against automated access. The exposed information reportedly includes names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers. The attacker published the data after claiming the company ignored their outreach. In an SEC filing, CenterPoint confirmed that “an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external-facing systems,” adding that an investigation is still ongoing and that affected customers will be notified. CenterPoint says its electric and gas services were not disrupted and does not expect a material financial impact. Multiple class-action lawsuits have already been filed in federal courts on behalf of affected customers; court filings allege the breach window ran from August 17 to September 1.
How to check if you’re affected
Affected products include any active or recent CenterPoint Energy account in Indiana, Minnesota, Ohio, or Texas. The company has not yet sent individual notifications, but if you are a current or former CenterPoint customer, assume your account data may be in the leaked set and take the following steps: place a free credit freeze with all three major bureaus (Equifax, Experian, TransUnion), monitor your credit report for accounts you did not open, and watch for phishing calls or emails using your correct address or account number as a trust-builder. The partial Social Security numbers in the breach are enough to combine with other leaked data for identity fraud.
