CenterPoint Energy Tells SEC Customer Data Was Stolen After 7.5Mn Records Advertised Online
CenterPoint Energy disclosed to federal regulators on Sept. 14 that an unauthorized party o 2026-9-16 12:46:36 Author: thecyberexpress.com(查看原文) 阅读量:4 收藏

CenterPoint Energy disclosed to federal regulators on Sept. 14 that an unauthorized party obtained personal information belonging to some of its customers through an external-facing system, days after a post on a cybercrime forum advertised a data set the seller said covered roughly 7.5 million customer records.

The Houston-based utility, which delivers electricity and natural gas to about 7 million metered customers across Indiana, Minnesota, Ohio and Texas, said in a Form 8-K that it learned of the online post this month and opened an investigation with outside forensic experts. It has reported the matter to law enforcement.

Operations were not affected. The filing states that the company’s “delivery of electric and gas services has not been impacted” and remains undisrupted — a distinction that matters for a utility, where regulators and customers draw a sharp line between the theft of billing records and interference with grid operations.

CenterPoint has not confirmed the volume or authenticity of the advertised data set, and has not described how the intruder got in or how long access persisted. The forum poster, using a hexadecimal-styled handle, claimed to have pulled the records from an API endpoint that lacked adequate authentication and rate limiting, and listed fields including customer names, phone numbers, email addresses, service and billing addresses, account and premise identifiers, billing amounts and past-due balances, billing and due dates, service and rate information, autopay and paperless billing status, driver’s license numbers, last four digits of Social Security numbers.

Also read: Origin Energy Data Breach Affects 900,000 Current and Former Customers

The actor claimed, additional identity information was exposed through a second account-verification function. According to the post, the extraction was split across seven parallel data ranges covering Texas and Minnesota. The actor said that security changes, including CAPTCHA enforcement, were eventually enforced and that prevented further data collection. These claims remain unverified.

Plaintiffs’ firms moved faster than the investigation. At least one has already announced an inquiry into potential claims on behalf of affected customers — now a standard sequel to any large consumer breach at a regulated utility.

The incident is not CenterPoint’s first brush with data exposure; the company was linked to earlier third-party file-transfer compromises, though analysts at the time judged much of that data to have originated outside its systems.


文章来源: https://thecyberexpress.com/centerpoint-energy-data-breach-sec-disclosure/
如有侵权请联系:admin#unsafe.sh