Cyber & AI intelligence
Wasteland.
Briefs indexed2939
Issues30
Published Mondays07:30 CT
▣ Breach CENTERPOINT-ENERGY 2026-09-30

CenterPoint Energy: API Scraping Breach Exposes Customer Data

"CenterPoint Energy (NYSE: CNP), the Houston-based utility that supplies electricity and natural gas to about 7 million metered customers in Indiana, Minnesota, Ohio and Texas, has confirmed a data breach. In a Form 8-K…"

CenterPoint Energy (NYSE: CNP), the Houston-based utility that supplies electricity and natural gas to about 7 million metered customers in Indiana, Minnesota, Ohio and Texas, has confirmed a data breach. In a Form 8-K filed with the U.S. Securities and Exchange Commission on September 14, 2026, the company said an "unauthorized third party obtained personal information relating to a portion of the Company's customers through one of the Company's external-facing systems." The filing came after a threat actor using the alias "4d722e4d656f77" said they had taken 7.49 million customer records and leaked them publicly. CenterPoint has not confirmed that figure, how many customers were affected, or what types of data were taken. The company says its electric and gas service was not disrupted.

What Happened

Reuters, SecurityWeek, BleepingComputer and FOX 26 Houston all quote the same 8-K language. According to the filing, CenterPoint became aware in September of an online post claiming to hold "a data set of certain customer information." The company then activated its incident response protocols, brought in third-party cybersecurity experts and took steps to further protect its systems. It said the investigation is ongoing and that it will notify affected customers and regulators as the law requires. SecurityWeek reports that the filing also says the company does not expect the incident to have a material impact.

The sources disagree on when the hacker first posted:

Breached.Company lists September 14 as the incident date, but that appears to be the filing date. No source gives an intrusion date, and CenterPoint has not said how long the system was exposed.

According to BleepingComputer, the actor leaked the data because they said CenterPoint ignored their messages and "treated them as a joke." SecurityWeek reports that the actor released a 2.5 GB archive and threatened: "next time we won't simply pull data, we'll start attacking the main infrastructure." SecurityWeek could not verify the data, and CenterPoint has not confirmed the leaked dataset is authentic.

SecurityPointBreak reports that at least five proposed class actions were filed in federal court before the 8-K was published. It names the firms as Shamis & Gentile and Lippe & Associates, suing on behalf of customers in Indiana, Texas and Minnesota. It also reports that Edelson Lechtzin LLP announced an investigation on September 10. Only that one lower-tier source reports the lawsuits, so treat them as reported rather than confirmed.

Analyst note: the alias "4d722e4d656f77" is hex-encoded ASCII for "Mr.Meow."

What Was Taken

CenterPoint's filing says only "personal information." All of the detail below comes from the attacker's claims, and the reported field lists differ between outlets:

Even without full SSNs, this combination of data is well suited to fraud. Names, addresses, account numbers, billing amounts and SSN last-four are enough to run convincing utility-themed phishing, "pay now or be disconnected" scams, and account takeover through customer support.

Why It Matters

The Attack Technique

CenterPoint has only said that access came "through one of the Company's external-facing systems." Everything more specific comes from the attacker:

This matches a Broken Object Level Authorization (BOLA/IDOR) flaw combined with unrestricted resource consumption, which are the top-ranked risks in the OWASP API Security Top 10. In this kind of attack, no exploit or malware is needed. A script can simply request every account ID in turn and receive a full record for each one. CyberSecureToday describes "anomalous query traffic" against a customer portal, which fits this account, but its claim that CenterPoint's security operations detected that traffic conflicts with the 8-K. The filing says the company learned of the incident from the attacker's public post.

What Organizations Should Do

  1. Check object-level authorization on every customer API. Every request for an account, premise or billing record should be checked against the authenticated session. Enumerable IDs should never return data on their own, and sequential identifiers should be replaced with non-guessable ones.
  2. Rate-limit and profile API traffic. Apply per-token and per-IP limits, put WAF or API-gateway protections in front of public endpoints, and alert on high-cardinality ID access. For example, one client requesting thousands of different account IDs is a strong signal of scraping.
  3. Find all your external APIs. Keep an inventory that includes legacy, mobile-app and partner APIs. Shadow and forgotten APIs are where enumeration flaws tend to survive.
  4. Monitor for your own data being sold. CenterPoint heard about this from a public post. Watching BreachForums-style venues and monitoring for leaked datasets can shorten the time between exfiltration and response.
  5. Warn customers about scams that use the leaked data. Tell customers that the company will never demand urgent payment by phone or text. Also tighten verification in call centres, where SSN last-four and account numbers can no longer be treated as proof of identity.
  6. Keep IT and OT tightly separated, and test it. Treat threats against infrastructure as credible. Regularly test that compromising a customer-facing system gives no route into operational networks.

Sources: CenterPoint Energy Confirms Breach, Hacker Claims 7.5M Files Breac... | CenterPoint Energy confirms customer data stolen in cyberattack | Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks... | CenterPoint Energy discloses customer data breach in SEC filing Re... | CenterPoint Energy confirms data breach after hacker claims 7.49M r... | CenterPoint Energy confirms data breach of customer personal inform... | CenterPoint Energy Breach Exposes 7.5M Records | CenterPoint Energy Form 8-K Breach Disclosure CyberSecureToday