A Houston-based utility serving 7 million electric and gas customers across four states has confirmed hackers stole customer data through one of its external-facing systems, after a threat actor claimed to have leaked nearly 7.5 million records on a hacking forum.
CenterPoint Energy filed an 8-K with the Securities and Exchange Commission Monday, saying it became aware in September of a third-party post claiming to hold a dataset of customer information. The company said its investigation found that hackers “obtained personal information relating to a portion of the Company’s customers” through the external system, and that electric and gas service delivery was not affected.
A threat actor using the alias “4d722e4d656f77” posted on the hacking forum BreachForums on Sept. 1, claiming to have extracted 7.49 million raw records and 6.73 million filtered records through a company-managed API the actor said lacked adequate authorization checks and rate limiting, according to a summary of the post tracked by the dark web monitoring account Dark Web Intelligence.
The claimed dataset includes customer names, phone numbers, service and billing addresses, account details, driver’s license numbers and the last four digits of Social Security numbers. CenterPoint has not verified the 7.49 million figure, the technical cause, or the authenticity of the leaked data, and has not published its own account of what was taken.
Notably, CenterPoint’s confirmation came after, not before, litigation began. Five proposed class-action suits were already filed in federal court against the utility last week, ahead of Monday’s 8-K, brought by Florida firm Shamis & Gentile and Dallas firm Lippe & Associates on behalf of customers in Indiana, Texas and Minnesota.
A separate firm, Edelson Lechtzin LLP, announced Sept. 10 that it was investigating similar claims on customers’ behalf. The suits place the breach window between Aug. 17 and Sept. 1 and allege CenterPoint’s online “guest bill pay” feature, which lets customers pay using only an account number, also returned a trove of personal data when the correct number was entered.
That theory hasn’t been confirmed by CenterPoint and conflicts with the leaked API claim in the forum post. One suit alleges the company “had the resources necessary to prevent the Data Breach but neglected to adequately invest” in security. None of the five suits has been certified as a class action.
The incident is unrelated to a 2023 breach CenterPoint disclosed last year, in which the Cl0p ransomware gang exploited a vulnerability in the MOVEit file-transfer software used by CLEAResult, a third-party vendor that manages energy-efficiency rebate programs for CenterPoint customers, according to a breach notification CLEAResult filed with Vermont’s Attorney General.
Cyberattacks on U.S. utilities jumped 234% year-over-year by the third quarter of 2024, averaging 1,339 weekly incidents, according to Check Point Research, as aging grid infrastructure and vendor-connected systems widen the sector’s attack surface.