Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen

Pierluigi Paganini
September 16, 2026

CenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information.

CenterPoint Energy admitted on Monday that an intruder stole personal information belonging to some of its customers. The Houston-based utility, which supplies electricity and gas to about 7 million accounts across Texas, Indiana, Minnesota and Ohio, disclosed the breach in an SEC filing after a hacker started advertising the data online.

“In September 2026, CenterPoint Energy, Inc. (the “Company”) became aware of an online post by a third party claiming to have obtained a data set containing certain of the Company’s customer information.” reads the FORM 8-K report filed with SEC.”While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external facing systems (the “Incident”).”

CenterPoint said its energy services were not affected. The company is investigating the breach, assessing exposed data, and will notify affected customers, regulators and law enforcement as required.

The company locked down its systems after seeing a post on a dark web forum where a hacker leaked data allegedly stolen from its systems.

On September 12, a threat actor using the alias “4d722e4d656f77” claimed on a cybercrime forum to have extracted roughly 7.49 million customer records from CenterPoint Energy.

“We’ve obtained well over 7.49 Million, each single one line which converts to 7 files in total of (.jsonl) format, which upholds per line 1 user, and we’ve obtained well over 7.49 million lines. As for the (CSV), we’ve filtered long text from (Jsonl), so the CSV will uphold the full PII (personal identity information).” the hacker claimed in the post. “It’s quite funny to think a $26.2 billion company has WEAK protection. We obtained said data from an API they managed and controlled, which lacked proper WAF protection, rate limiting, certification protection, and no JWT/Auth token to pull said data. Mid the 7.49 million mark, they did an attempt to stop us dumping data, which, with a simple CAPTCHA key, in terms, we would have pulled 17.44 million data from said company.”

The hacker claimed the theft of names, phone numbers, service and billing addresses, account numbers, billing amounts, payment status and partial Social Security numbers. He offered a 2.5 GB archive for download. The attacker warned that “next time we won’t simply pull data, we’ll start attacking the main infrastructure,” a line that reads well on a forum but should still be taken seriously by any critical infrastructure operator.

The attackers claim they stole over 7.49 million records through an API they say lacked proper WAF protection, rate limiting and authentication. They also claim the company tried to stop the data dump only after millions of records had been extracted.

CenterPoint’s SEC filing does not name the threat actor, confirm the 7.49 million figure or detail exactly which fields were exposed. It only states that an unauthorized third party obtained personal information “relating to a portion of the Company’s customers through one of the Company’s external-facing systems.” Independent outlets have not been able to fully validate the leaked dataset, and attackers often inflate numbers or repackage old data, so the final scope may differ from the claims.

For now, the takeaway is simple. If you are a CenterPoint customer, assume that your name, address, account details and at least part of your Social Security number may have been exposed. Be careful with targeted phishing, credential-stuffing attacks and fake billing messages that use this information to look legitimate.

The same risk applies across the sector. Internet-facing systems, weak API security and misconfigured services can give attackers an easy way in, while companies may struggle to detect and stop the attack before data is stolen.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)







Click Here For The Original Source.

——————————————————–

..........

.

.