Skip to content
Data breachOngoing

CenterPoint Energy confirms customer data breach after hacker claims 7.49 million records stolen via unsecured API

CenterPoint Energy confirmed unauthorized access to customer data through an external system after a hacker claimed to have pulled 7.49 million records from an API lacking authentication.

Victim
CenterPoint Energy
records
7.5M

On 16 September 2026, CenterPoint Energy โ€” the Houston-based electric and natural gas utility serving millions of customers across several U.S. states โ€” confirmed that an unauthorized third party had accessed customer information held in one of its external systems, after a threat actor publicly claimed to have stolen a large database from the company.

The claim first surfaced on 1 September 2026, when a user posting under the handle "4d722e4d656f77" advertised a data set said to belong to CenterPoint on an open-web forum. In a Form 8-K filed with the U.S. Securities and Exchange Commission on 14 September, the company said it had become aware of the online post and had launched an investigation with outside experts. Reporting confirming the breach appeared on 16 September.

An exposed API

According to the attacker's account, the records were pulled through an application programming interface that had no web application firewall, no rate limiting, no certificate checks and no authentication token, allowing automated extraction to continue until a CAPTCHA interrupted the download at roughly 7.49 million lines โ€” a figure CenterPoint has not confirmed. The fields listed in the sample included customer names, phone numbers, service and billing addresses, account and premise identifiers, billing amounts and due dates, autopay and paperless-billing status, rate class, email addresses, driver's license numbers and the last four digits of Social Security numbers.

Response

CenterPoint said full financial account details were not part of the exposed data set, and that it would notify affected customers and regulators as required by law. With the investigation into the scope and authenticity of the leaked data still under way, the incident's status remained ongoing at the time of disclosure.

Timeline

  1. A threat actor using the handle "4d722e4d656f77" advertises a data set claimed to belong to CenterPoint Energy on an open-web forum.

  2. CenterPoint files a Form 8-K with the U.S. Securities and Exchange Commission acknowledging awareness of the online post and an ongoing investigation.

  3. Reporting confirms CenterPoint's disclosure that an unauthorized third party accessed customer data through an external system.

Sources

  1. helpnetsecurity.comhttps://www.helpnetsecurity.com/2026/09/16/centerpoint-energy-data-breach-hacker-claims/
  2. cyberinsider.comhttps://cyberinsider.com/centerpoint-energy-confirms-data-breach-after-hacker-claims-7-49m-records/
  3. foxnews.comhttps://www.foxnews.com/tech/hacker-claims-7-49m-customer-records-stolen-from-american-utility-company

Related incidents