CenterPoint Energy Confirms Customer Data Stolen as Hacker Claims 7.49 Million Records in Utility Breach

CenterPoint Energy has disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company.
An investigation started after the company discovered an online post from a threat actor claiming to have stolen 7.49 million records. CenterPoint Energy is a Houston-based public utility that provides electric and natural gas services and operates power generation facilities, serving approximately 7 million metered customers across Indiana, Minnesota, Ohio and Texas, employing roughly 8,300 people and generating over 9.3 billion dollars in annual revenue.
## What the Hacker Claims
Earlier this month, a threat actor using the alias 4d722e4d656f77 told BleepingComputer they stole 7.49 million customer records including names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers.
The threat actor leaked the data, claiming that the company ignored their messages and treated them as a joke.
According to the intruder, they exfiltrated the data by iterating through millions of IDs on CenterPoint's public API, which lacked rate limiting, web application firewall protection and other security measures against automated access.
## The Company's Confirmation
In a filing with the US Securities and Exchange Commission, CenterPoint Energy confirms that data was stolen, but does not name the threat actor, the number of affected customers, or the types of compromised data.
"While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company's customers through one of the Company's external-facing systems," the filing reads.
"The Company is continuing to work with third-party experts to determine the scope of customers and personal information affected by the incident and intends to notify affected customers and regulatory authorities as required by applicable law."
CenterPoint Energy said its electric and gas services were not impacted by the cyberattack, and that it does not believe the incident will materially affect its business or financial condition. The company has activated its incident-response procedures, hired third-party cybersecurity experts, strengthened protections on its systems, and reported the incident to law enforcement and regulators.
## Lawsuits Pile Up
Multiple lawsuits proposing class actions against the firm have already been filed in federal courts by law firms representing potentially impacted customers, alleging the data breach occurred between August 17 and September 1.
The litigation will test how courts treat a breach that required no sophisticated intrusion at all: the attacker's account describes a systematically exposed public interface rather than a hacked perimeter. If confirmed, the case becomes a reference point for utilities' obligations to secure customer-facing APIs โ the plumbing through which smart meters, billing portals and mobile apps increasingly operate.
For customers, the partial Social Security numbers are the sharpest concern, since combinations of names, addresses and partial SSNs feed identity-theft attempts that can surface years later. The company's commitment to notify affected customers and regulators will determine how quickly the roughly 7 million metered customers across its four-state footprint learn whether their records were among those taken.
The breach also lands amid a string of major data incidents this year, from Australian energy provider Origin's disclosure of exposed client data to an IDScan breach tied to 153 million stolen driver's licences โ a cluster that regulators and litigants are unlikely to treat as coincidence.
## A Breach Without a Break-In
Security researchers have long warned that application programming interfaces โ the machine-to-machine doors between a company and its apps, partners and websites โ are among the least monitored parts of corporate infrastructure. The attacker account in this case describes exactly that gap: no exploit, no malware, no stolen credentials, just millions of automated requests that the system answered because nothing stopped it.
Rate limiting and web application firewalls are standard defences documented in every major security framework, which is why their absence, if confirmed by the investigation, will feature prominently in the class-action filings. Plaintiffs will argue that a utility holding partial Social Security numbers owes a duty of care that extends to its public interfaces; the company will argue that no system can be made perfectly secure.
The gap between the two filings is also notable. The threat actor claims 7.49 million records with specific fields; the SEC filing confirms theft occurred but names no figures. Regulators generally require precision in eventual customer notifications, so the company public number โ when disclosed โ will either corroborate or undercut the attacker total, and both outcomes carry consequences: over-confirmation invites liability, while under-confirmation invites accusations of minimisation.
The case also arrives as US regulators sharpen their attention on critical infrastructure cyber hygiene. Energy utilities sit atop that list, and a breach that plausibly stemmed from misconfigured public infrastructure will feed directly into rulemaking debates about mandatory API security standards for essential services.
For now, the company message is continuity: services unaffected, business unhurt, response activated. The lawsuits, the regulator notifications and the eventual customer notices will decide whether that framing holds.
Discussion
Recommended for you
More technology
Cybersecurity
Hackers Exploit VPN Flaw to Breach Japan's Digital Agency and Access 240,000 People's Data
9/16/2026
Cybersecurity
Global Ransomware Attacks Hit Record 997 in August as Utilities Surge
9/16/2026
Cybersecurity
ICE to Purchase Robot Dogs From Boston Dynamics for Officer Safety
9/2/2026
Cybersecurity