CenterPoint Energy Confirms Customer Data Breach Amid Hacker Claims of 7.49 Million Records Stolen
The utility company has acknowledged unauthorized access to customer information, while a hacker alleges a massive theft of data including partial Social Security numbers.
CenterPoint Energy has confirmed that a cybersecurity incident resulted in the exposure of personal information belonging to some of its customers. The Houston-based utility company disclosed the breach in a filing with the U.S. Securities and Exchange Commission (SEC) on September 14, stating it became aware of an online post from a third party claiming to possess a data set containing customer information.
Following this discovery, CenterPoint Energy initiated its cybersecurity incident response protocols and engaged external cybersecurity experts. The company's investigation determined that an unauthorized third party gained access to personal information through one of its external-facing systems. CenterPoint has not yet disclosed the total number of affected customers or the specific types of data compromised, but intends to notify affected customers and regulators as required once the full scope is determined.
A hacker, operating under the alias "4d722e4d656f77," has claimed responsibility for stealing 7.49 million CenterPoint customer records. According to the hacker, this data includes names, phone numbers, service and billing addresses, CenterPoint account numbers, billing amounts, and partial Social Security numbers. The threat actor also alleged that the breach was facilitated by exploiting a public CenterPoint API, which they claim lacked adequate protections against automated data access requests, such as effective rate limiting or web application firewall measures. CenterPoint Energy has confirmed that customer information was stolen but has not corroborated the hacker's specific figures or the detailed list of compromised data.
Despite the breach, CenterPoint Energy stated that its electric and natural gas services continued to operate normally and that it does not anticipate a material financial impact from the incident. The company declined to provide further details beyond its SEC filing when contacted for comment.
The potential value of stolen utility records lies in their ability to lend credibility to scams. Information such as names, addresses, and account numbers can be used by criminals to craft convincing phishing attempts or fraudulent communications, making it appear they possess legitimate knowledge of the customer's relationship with the utility company. Scammers may leverage such data, combined with information from other breaches, to impersonate the utility and demand immediate payments or personal information, often creating a sense of urgency.
CenterPoint Energy has advised customers to watch for official breach notices and to be skeptical of any unsolicited communications claiming to be from the company, especially those demanding immediate action or payment. Customers are encouraged to verify any such requests directly through official channels, such as the company's website or the customer service number listed on their bills, rather than relying on contact information provided in suspicious messages.
In response to potential fallout from data breaches, cybersecurity experts recommend several protective measures. These include monitoring credit reports and financial accounts for unauthorized activity, securing online accounts with strong, unique passwords and enabling two-factor authentication, and considering a credit freeze if sensitive information like Social Security numbers is confirmed to be compromised. Additionally, vigilance against phishing attempts and the use of robust antivirus software are advised to mitigate the risk of malware infections or further data compromise.