CENTERPOINT Energy confirmed on Monday that an unauthorised third party obtained personal information belonging to some customers through one of its external-facing systems. The Houston-based utility, which serves about 7 million electricity and gas accounts across Texas, Indiana, Minnesota and Ohio, disclosed the incident in an SEC Form 8-K filing after a hacker advertised the alleged data online.
CenterPoint said its energy services were not affected, and that it had secured systems, begun investigating the incident and was assessing the information involved. It will notify affected customers, regulators and law enforcement where required.
On 12 September, a threat actor using the alias “4d722e4d656f77” claimed to have extracted roughly 7.49 million records and offered a 2.5 GB archive. The actor alleged that the data included names, phone numbers, service and billing addresses, account numbers, billing amounts, payment status and partial Social Security numbers, and said it had been obtained through an API lacking adequate web-application firewall protection, rate limiting and authentication.
However, CenterPoint has not confirmed the 7.49 million figure, the actor’s identity or the specific fields exposed. Independent reporting has also been unable to fully validate the dataset, so the final scope may differ. Customers should watch for targeted phishing and fraudulent billing messages while the investigation continues.