CenterPoint Energy Confirms Customer Data Theft After Hacker Publishes Alleged Leak

CenterPoint Energy confirms customer data theft in alleged 7.5M-record breach exposing names, accounts and partial SSNs. Services unaffected.

Text generated by artificial intelligence, published without human review. AI transparency

CenterPoint Energy Confirms Customer Data Theft After Hacker Publishes Alleged Leak
Data Breaches

Illustrative image generated with AI

Listen to this articleAudio edition · 10 min

CenterPoint Energy has confirmed that an unauthorized party obtained personal information belonging to some customers through an internet-facing company system.

The Houston-based electricity and natural-gas utility disclosed the incident on September 15, 2026, after investigating an online post advertising data allegedly stolen from the company. CenterPoint has not revealed how many customers were affected, which data fields were compromised, or how the attacker gained access.

A threat actor claims to have extracted approximately 7.49 million to 7.5 million records. That figure remains unverified and may refer to database rows, accounts, or duplicated entries rather than individual people.

CenterPoint said the breach did not interrupt electricity or gas delivery. It also does not expect the incident to materially affect its business operations or financial condition.

What CenterPoint Has Confirmed

CenterPoint learned of a threat-actor post claiming that company data had been stolen and subsequently began an investigation. According to its filing with the U.S. Securities and Exchange Commission, investigators determined that an unauthorized third party had acquired personal information associated with a portion of its customers.

The compromised environment was described only as an “external-facing” system. CenterPoint has not identified the application, API, hosting arrangement, software platform, or vulnerability involved.

Several other central questions remain unanswered:

  • The number of affected customers
  • The categories of personal information exposed
  • The volume of information obtained
  • The attacker’s identity
  • The initial access method
  • Whether the affected system was hosted internally or by a third party
  • Whether the stolen records could be used to access or modify customer accounts

CenterPoint serves approximately seven million metered customers across Indiana, Minnesota, Ohio, and Texas. The alleged leak contains more records than that customer figure, but the comparison does not establish that every customer was affected. A single person or account could appear in multiple records.

The company’s confirmation separates the incident from an entirely unsupported extortion claim: some customer information was taken. The scale and composition of the stolen dataset, however, are still being investigated.

The Alleged Leak Includes Account and Identity Data

The attacker, identified by the alias 4d722e4d656f77, reportedly claimed responsibility for taking 7.49 million customer records. The alleged contents include names, telephone numbers, service addresses, billing addresses, account numbers, billing amounts, and partial Social Security numbers.

Another description of the dataset refers to approximately 7.5 million records containing names, account details, billing information, and the final four Social Security number digits. CenterPoint has not confirmed any of those specific fields.

Claims concerning the leaked material appeared on a cybercrime forum on September 12. A 2.5 GB archive was subsequently made available for download, according to SecurityWeek’s account of the disclosure. Its authenticity could not be independently validated.

That distinction matters. Criminal forum posts often mix genuine samples with duplicated, outdated, repackaged, or fabricated information. CenterPoint’s investigation confirms data acquisition, but it does not yet validate the archive, the advertised record count, or the attacker’s complete description.

The actor also reportedly threatened that a later operation would target CenterPoint’s “main infrastructure.” There is no evidence that operational technology, power-generation systems, or utility-delivery networks were compromised. Electricity and natural-gas services continued operating.

An API Enumeration Attack Is Claimed but Not Proven

The only detailed account of the intrusion method comes from the alleged attacker. According to BleepingComputer’s reporting on the technical claim, the actor said data was collected by automatically testing millions of identifiers against a publicly accessible CenterPoint API.

The attacker alleged that the interface lacked effective rate limiting, web application firewall protection, and controls capable of detecting or blocking automated enumeration. CenterPoint has not confirmed that explanation.

If accurate, the activity would resemble high-volume object enumeration rather than a conventional malware deployment. An automated client could submit large numbers of identifiers, record successful responses, and gradually assemble a substantial dataset.

Several conditions can make such attacks possible. Identifiers may be predictable, authorization checks may fail to verify that a requester is entitled to view a record, or the application may permit an abnormal number of requests without intervention. The available information does not establish which, if any, of these weaknesses existed.

There is also no disclosed vulnerability identifier, affected software version, patch, API redesign, authentication change, or rate-limit configuration. Customers and defenders should therefore treat the API narrative as unverified threat intelligence, not the established root cause.

Customers Face Phishing, Fraud, and Impersonation Risks

The immediate impact is a privacy breach rather than an interruption of essential services. Its eventual severity depends heavily on which fields CenterPoint confirms.

Names, addresses, telephone numbers, account details, and billing information could help criminals create convincing utility-themed messages. A scammer could reference a service address or recent billing amount while demanding payment, requesting credentials, or threatening disconnection.

Partial Social Security numbers are not equivalent to complete numbers, but they can strengthen identity-verification scams when combined with names, addresses, and account information. Exposed account identifiers could also create additional risk if CenterPoint systems use them in customer-service or recovery workflows.

Potentially affected customers should be cautious about unsolicited calls, emails, and text messages claiming to concern unpaid bills, refunds, service problems, or breach compensation. Requests should be verified through a known CenterPoint channel rather than contact details supplied in the message.

Customers can also review utility and financial accounts for unexplained changes or transactions. CenterPoint has not announced a specific identity-protection service, mandatory credential reset, or customer-facing remediation program.

Multiple proposed class-action lawsuits have reportedly been filed in federal courts. The complaints allege that the breach occurred between August 17 and September 1, but CenterPoint has not confirmed that incident window.

Investigation Continues Without a Public Technical Fix

CenterPoint has activated its incident-response procedures and engaged outside cybersecurity specialists. The investigation is intended to identify the affected population, determine which information was obtained, and establish how the compromise occurred.

The utility also said it had strengthened system protections, although it did not describe the changes. No specific patch, firewall deployment, API control, credential rotation, or monitoring rule has been disclosed.

The incident has been reported to law enforcement and regulators. CenterPoint plans to notify customers and relevant authorities where required by law, according to reporting on the company’s regulatory disclosure.

Until individual notices are issued, customers cannot determine from the public information alone whether their records were included. Any legitimate notification should clarify the exposed data fields, the known incident period, and the protections being offered.

For CenterPoint and other utilities, useful forensic evidence would include bursts of API requests, sequential identifier queries, unusually high response volumes, repeated access from a small set of infrastructure, and large outbound transfers. CenterPoint has not published any indicators of compromise.

Earlier CenterPoint Data Claims Had a Different Origin

CenterPoint has previously appeared in data-sale and access-broker claims. In 2024, an actor known as AntiBrok3rs reportedly listed access or information connected to the utility, while another actor separately claimed to possess CenterPoint data.

Analysts associated those earlier datasets with the Cl0p ransomware group’s 2023 MOVEit campaign. The information was believed to have originated from a third party rather than from CenterPoint’s own systems.

No connection has been established between those events and the newly confirmed compromise. The present incident has not been attributed to Cl0p, AntiBrok3rs, or any recognized threat group.

For now, the clearest conclusion is narrower: attackers obtained customer personal information through an external-facing CenterPoint system, while the number of victims, exact data fields, and technical cause remain unknown.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsCenterPoint Energy breachcustomer data theftutility data leakAPI enumeration attackpersonal information exposedcybersecurity incident
Back to home