CenterPoint Energy Reports Data Breach, Customer Information Compromised
On September 14, 2025, CenterPoint Energy, a utility company based in Houston, Texas, confirmed a significant data breach that has raised alarms regarding the security of customer information. The breach was identified when an unauthorized third party accessed sensitive customer data through one of the company’s external-facing systems. Following the incident, CenterPoint activated its cybersecurity incident response procedures and enlisted the help of outside security experts to investigate the breach thoroughly.
Despite the acknowledgment of the data breach, CenterPoint has not disclosed the specific number of customers affected or the types of personal information that were accessed by the unauthorized entity. The company has stated it will notify affected customers and regulatory bodies once the investigation concludes and the full extent of the breach is known.
The situation took a concerning turn when a threat actor operating under the alias "4d722e4d656f77" claimed responsibility for the incident, asserting they had stolen 7.49 million customer records from CenterPoint. The attacker went further, allegedly leaking a portion of the data after receiving no response from CenterPoint regarding the breach. According to this individual, the compromised records include critical customer information, such as names, service addresses, phone numbers, email addresses, account numbers, billing information, and even partial Social Security numbers. However, CenterPoint has yet to independently verify the accuracy of these claims or the specifics of the data that the attacker alleges were exposed.
In discussions with security researchers, the hacker provided insights into the methods used to execute the breach. They revealed that the attack was facilitated by cycling through millions of customer IDs utilizing a public API from CenterPoint. Alarmingly, it was noted that the API was lacking effective rate limiting or web application firewall provisions that could have potentially obstructed mass automated requests. CenterPoint’s filings with the Securities and Exchange Commission (SEC) merely confirm that the breach occurred via an external-facing system, without delving into the technical details of the method employed by the attacker. Furthermore, the company has not responded to inquiries for additional information beyond its regulatory statements.
The fallout from this breach raises significant concerns for customers whose information may have been compromised. Scammers could exploit the utility account details to conduct convincing phishing attacks, leveraging the personal information that is now potentially in their hands. A criminal armed with a customer’s name, service address, and account number could convincingly impersonate CenterPoint, making it easier to deceive victims into making fraudulent payments or divulging additional sensitive information. The partial Social Security numbers could pose a further risk, as they might be combined with data from other breaches to facilitate identity theft.
In light of these developments, CenterPoint customers are urged to exercise heightened vigilance concerning any suspicious communications claiming to be from the utility company. This caution is particularly important for messages that create urgency around account verification or payments. Individuals who suspect their information may be compromised are encouraged to monitor their credit reports for unauthorized activities. They should also consider placing credit freezes with major credit bureaus should Social Security information be involved, in addition to enabling two-factor authentication on critical accounts.
Customers receiving breach notifications are advised to independently verify them through official company channels rather than responding to unsolicited communications. Awareness of possible phishing attempts is crucial, as these may persist long after the initial breach is disclosed.
As the investigation into the breach continues, it serves as a stark reminder of the vulnerabilities that exist in cybersecurity and highlights the need for companies to adopt robust protective measures to safeguard customer data.
For further updates, customers and stakeholders may refer to formal company announcements and relevant regulatory filings.
Source: Fox News

