CenterPoint Energy confirms customer data stolen in cyberattack
CenterPoint Energy, a major US utility company, disclosed a data breach involving unauthorized access to customer personal information. The attacker exploited a public API lacking rate limiting and WAF protections to exfiltrate approximately 7.49 million customer records, including names, phone numbers, addresses, account numbers, billing amounts, and partial Social Security numbers. The breach was discovered after the attacker publicly leaked the data and claimed the company ignored their messages. CenterPoint Energy confirmed the breach in an SEC filing but has not disclosed the full scope or specific data types affected. The company has activated incident response, engaged cybersecurity experts, and reported the incident to law enforcement and regulators. Lawsuits have been filed alleging the breach occurred between August 17 and September 1. The company states its core electric and gas services were not impacted and does not expect material business or financial effects.
AI Analysis
Technical Summary
An unauthorized third party exploited security weaknesses in CenterPoint Energy's public-facing API, which lacked rate limiting and web application firewall protections, to systematically access and exfiltrate approximately 7.49 million customer records. The stolen data includes personal identifiers such as names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers. The attacker publicly leaked the data after claiming the company ignored their ransom-like messages. CenterPoint Energy confirmed the breach in an SEC filing, acknowledging unauthorized access to customer personal information through an external system. The company is investigating the full scope, notifying affected customers and regulators as required, and has taken steps to strengthen system protections and engage law enforcement. Multiple class action lawsuits have been filed related to the incident.
Potential Impact
The breach exposed sensitive personal information of millions of customers, including partial Social Security numbers and billing details, which could increase the risk of identity theft and fraud for affected individuals. Although the company states that electric and gas services were not impacted and does not anticipate material business disruption, the exposure of personal data may lead to reputational damage, regulatory scrutiny, and legal consequences, as evidenced by ongoing class action lawsuits.
Mitigation Recommendations
CenterPoint Energy has activated its incident response procedures, engaged third-party cybersecurity experts, strengthened protections on its external systems, and reported the incident to law enforcement and regulatory authorities. Customers should be notified as required by law. Organizations should ensure public APIs have appropriate security controls such as rate limiting and web application firewalls to prevent automated data harvesting. Since the vendor is managing remediation and investigation, no additional immediate action is recommended beyond monitoring official communications for updates.
CenterPoint Energy confirms customer data stolen in cyberattack
Description
CenterPoint Energy, a major US utility company, disclosed a data breach involving unauthorized access to customer personal information. The attacker exploited a public API lacking rate limiting and WAF protections to exfiltrate approximately 7.49 million customer records, including names, phone numbers, addresses, account numbers, billing amounts, and partial Social Security numbers. The breach was discovered after the attacker publicly leaked the data and claimed the company ignored their messages. CenterPoint Energy confirmed the breach in an SEC filing but has not disclosed the full scope or specific data types affected. The company has activated incident response, engaged cybersecurity experts, and reported the incident to law enforcement and regulators. Lawsuits have been filed alleging the breach occurred between August 17 and September 1. The company states its core electric and gas services were not impacted and does not expect material business or financial effects.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
An unauthorized third party exploited security weaknesses in CenterPoint Energy's public-facing API, which lacked rate limiting and web application firewall protections, to systematically access and exfiltrate approximately 7.49 million customer records. The stolen data includes personal identifiers such as names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers. The attacker publicly leaked the data after claiming the company ignored their ransom-like messages. CenterPoint Energy confirmed the breach in an SEC filing, acknowledging unauthorized access to customer personal information through an external system. The company is investigating the full scope, notifying affected customers and regulators as required, and has taken steps to strengthen system protections and engage law enforcement. Multiple class action lawsuits have been filed related to the incident.
Potential Impact
The breach exposed sensitive personal information of millions of customers, including partial Social Security numbers and billing details, which could increase the risk of identity theft and fraud for affected individuals. Although the company states that electric and gas services were not impacted and does not anticipate material business disruption, the exposure of personal data may lead to reputational damage, regulatory scrutiny, and legal consequences, as evidenced by ongoing class action lawsuits.
Defensive Guidance
CenterPoint Energy has activated its incident response procedures, engaged third-party cybersecurity experts, strengthened protections on its external systems, and reported the incident to law enforcement and regulatory authorities. Customers should be notified as required by law. Organizations should ensure public APIs have appropriate security controls such as rate limiting and web application firewalls to prevent automated data harvesting. Since the vendor is managing remediation and investigation, no additional immediate action is recommended beyond monitoring official communications for updates.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6aa9766f55bf5e2cf5195d19
Added to database: 09/15/2026, 16:46:39 UTC
Last enriched: 09/15/2026, 16:46:46 UTC
Last updated: 09/16/2026, 02:11:26 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.