Broken shield icon beside the CenterPoint Energy logo with digital identity cards scattering away

CenterPoint Energy Breach Exposes 7.5 Million Customer Records

CenterPoint Energy told regulators an unauthorized party accessed customer data, days after a hacker began advertising millions of records for download.

A Houston-based utility serving 7 million electric and gas customers across four states has confirmed hackers stole customer data through one of its external-facing systems, after a threat actor claimed to have leaked nearly 7.5 million records on a hacking forum.

CenterPoint Energy filed an 8-K with the Securities and Exchange Commission Monday, saying it became aware in September of a third-party post claiming to hold a dataset of customer information. The company said its investigation found that hackers “obtained personal information relating to a portion of the Company’s customers” through the external system, and that electric and gas service delivery was not affected.

Beyond the Break weekly cybersecurity newsletter — Subscribe

A threat actor using the alias “4d722e4d656f77” posted on the hacking forum BreachForums on Sept. 1, claiming to have extracted 7.49 million raw records and 6.73 million filtered records through a company-managed API the actor said lacked adequate authorization checks and rate limiting, according to a summary of the post tracked by the dark web monitoring account Dark Web Intelligence.

The claimed dataset includes customer names, phone numbers, service and billing addresses, account details, driver’s license numbers and the last four digits of Social Security numbers. CenterPoint has not verified the 7.49 million figure, the technical cause, or the authenticity of the leaked data, and has not published its own account of what was taken.

Notably, CenterPoint’s confirmation came after, not before, litigation began. Five proposed class-action suits were already filed in federal court against the utility last week, ahead of Monday’s 8-K, brought by Florida firm Shamis & Gentile and Dallas firm Lippe & Associates on behalf of customers in Indiana, Texas and Minnesota.

A separate firm, Edelson Lechtzin LLP, announced Sept. 10 that it was investigating similar claims on customers’ behalf. The suits place the breach window between Aug. 17 and Sept. 1 and allege CenterPoint’s online “guest bill pay” feature, which lets customers pay using only an account number, also returned a trove of personal data when the correct number was entered.

That theory hasn’t been confirmed by CenterPoint and conflicts with the leaked API claim in the forum post. One suit alleges the company “had the resources necessary to prevent the Data Breach but neglected to adequately invest” in security. None of the five suits has been certified as a class action.

The incident is unrelated to a 2023 breach CenterPoint disclosed last year, in which the Cl0p ransomware gang exploited a vulnerability in the MOVEit file-transfer software used by CLEAResult, a third-party vendor that manages energy-efficiency rebate programs for CenterPoint customers, according to a breach notification CLEAResult filed with Vermont’s Attorney General.

Cyberattacks on U.S. utilities jumped 234% year-over-year by the third quarter of 2024, averaging 1,339 weekly incidents, according to Check Point Research, as aging grid infrastructure and vendor-connected systems widen the sector’s attack surface.

Total
0
Shares
Previous Article
AI agent control plane managing multiple autonomous agents, tools, credentials, data and security controls

Eight Vendors Weigh In on Controlling AI

Next Article
Malicious email compromises a Cisco Secure Email Gateway, gains root access and erases logs while a replacement appliance is rebuilt.

Cisco Says Patching Exploited Email Gateway Zero-Day May Not Be Enough

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading