CenterPoint Energy (NYSE: CNP), the Houston-based utility that supplies electricity and natural gas to about 7 million metered customers in Indiana, Minnesota, Ohio and Texas, has confirmed a data breach. In a Form 8-K filed with the U.S. Securities and Exchange Commission on September 14, 2026, the company said an "unauthorized third party obtained personal information relating to a portion of the Company's customers through one of the Company's external-facing systems." The filing came after a threat actor using the alias "4d722e4d656f77" said they had taken 7.49 million customer records and leaked them publicly. CenterPoint has not confirmed that figure, how many customers were affected, or what types of data were taken. The company says its electric and gas service was not disrupted.
What Happened
Reuters, SecurityWeek, BleepingComputer and FOX 26 Houston all quote the same 8-K language. According to the filing, CenterPoint became aware in September of an online post claiming to hold "a data set of certain customer information." The company then activated its incident response protocols, brought in third-party cybersecurity experts and took steps to further protect its systems. It said the investigation is ongoing and that it will notify affected customers and regulators as the law requires. SecurityWeek reports that the filing also says the company does not expect the incident to have a material impact.
The sources disagree on when the hacker first posted:
- SecurityWeek dates the forum claims to September 12.
- SecurityPointBreak says the BreachForums post went up on September 1, citing a summary tracked by the Dark Web Intelligence monitoring account.
- BleepingComputer says only that the actor contacted it "earlier this month."
Breached.Company lists September 14 as the incident date, but that appears to be the filing date. No source gives an intrusion date, and CenterPoint has not said how long the system was exposed.
According to BleepingComputer, the actor leaked the data because they said CenterPoint ignored their messages and "treated them as a joke." SecurityWeek reports that the actor released a 2.5 GB archive and threatened: "next time we won't simply pull data, we'll start attacking the main infrastructure." SecurityWeek could not verify the data, and CenterPoint has not confirmed the leaked dataset is authentic.
SecurityPointBreak reports that at least five proposed class actions were filed in federal court before the 8-K was published. It names the firms as Shamis & Gentile and Lippe & Associates, suing on behalf of customers in Indiana, Texas and Minnesota. It also reports that Edelson Lechtzin LLP announced an investigation on September 10. Only that one lower-tier source reports the lawsuits, so treat them as reported rather than confirmed.
Analyst note: the alias "4d722e4d656f77" is hex-encoded ASCII for "Mr.Meow."
What Was Taken
CenterPoint's filing says only "personal information." All of the detail below comes from the attacker's claims, and the reported field lists differ between outlets:
- Volume: Every source reports the attacker's figure of about 7.49 million records, rounded to 7.5M by some. SecurityPointBreak adds that the post described 7.49 million raw records and 6.73 million "filtered" records, which suggests duplicates were removed. The raw count is close to CenterPoint's entire customer base of roughly 7 million, so the claim implies nearly every customer was affected. CenterPoint has said only "a portion."
- Fields reported by BleepingComputer: names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers.
- Additional fields in some reports: CyberInsider adds email addresses and account and premise identifiers. SecurityPointBreak adds driver's license numbers and specifies the SSN data as the last four digits.
- Unsupported claims: CyberSecureToday says the exposed data included utility meter identifiers, and that CenterPoint enforced credential resets and deployed web application firewall (WAF) monitoring. No other source supports these claims. CyberSecureToday also gives customer counts (2.7M electric, 4.7M gas) and a service area that includes Louisiana, which conflict with the roughly 7M customers in four states reported elsewhere.
Even without full SSNs, this combination of data is well suited to fraud. Names, addresses, account numbers, billing amounts and SSN last-four are enough to run convincing utility-themed phishing, "pay now or be disconnected" scams, and account takeover through customer support.
Why It Matters
- The attacker is threatening operational systems. There is no evidence that operational technology was touched, and CenterPoint says service delivery was unaffected. Still, a named actor has now publicly threatened a utility that serves millions of people in four states. CyberSecureToday says OT/SCADA networks were "completely isolated," but that is not in any quoted 8-K text and should not be treated as confirmed.
- CenterPoint has been named before. SecurityWeek notes that in 2024 an access broker called AntiBrok3rs listed CenterPoint among several energy companies it targeted, and a different hacker later claimed to have its data. Utilities that keep appearing in these claims are being actively probed.
- Disclosure followed the attacker. CenterPoint's own account says it began investigating after it saw a public post. It did not detect the exfiltration itself. If the reported lawsuits are accurate, litigation also started before the company disclosed.
- Customer-facing APIs are a weak point. For critical infrastructure, the systems that serve customers are often less protected than the grid control systems, and they hold the data that fraudsters want.
The Attack Technique
CenterPoint has only said that access came "through one of the Company's external-facing systems." Everything more specific comes from the attacker:
- In statements to BleepingComputer, the actor said they iterated through millions of sequential IDs on a public CenterPoint API. They said the API had no rate limiting, no WAF protection and no other defence against automated access.
- CyberInsider and SecurityPointBreak, both summarising the forum post, add that the endpoint lacked adequate authentication or authorization checks.
This matches a Broken Object Level Authorization (BOLA/IDOR) flaw combined with unrestricted resource consumption, which are the top-ranked risks in the OWASP API Security Top 10. In this kind of attack, no exploit or malware is needed. A script can simply request every account ID in turn and receive a full record for each one. CyberSecureToday describes "anomalous query traffic" against a customer portal, which fits this account, but its claim that CenterPoint's security operations detected that traffic conflicts with the 8-K. The filing says the company learned of the incident from the attacker's public post.
What Organizations Should Do
- Check object-level authorization on every customer API. Every request for an account, premise or billing record should be checked against the authenticated session. Enumerable IDs should never return data on their own, and sequential identifiers should be replaced with non-guessable ones.
- Rate-limit and profile API traffic. Apply per-token and per-IP limits, put WAF or API-gateway protections in front of public endpoints, and alert on high-cardinality ID access. For example, one client requesting thousands of different account IDs is a strong signal of scraping.
- Find all your external APIs. Keep an inventory that includes legacy, mobile-app and partner APIs. Shadow and forgotten APIs are where enumeration flaws tend to survive.
- Monitor for your own data being sold. CenterPoint heard about this from a public post. Watching BreachForums-style venues and monitoring for leaked datasets can shorten the time between exfiltration and response.
- Warn customers about scams that use the leaked data. Tell customers that the company will never demand urgent payment by phone or text. Also tighten verification in call centres, where SSN last-four and account numbers can no longer be treated as proof of identity.
- Keep IT and OT tightly separated, and test it. Treat threats against infrastructure as credible. Regularly test that compromising a customer-facing system gives no route into operational networks.
Sources: CenterPoint Energy Confirms Breach, Hacker Claims 7.5M Files Breac... | CenterPoint Energy confirms customer data stolen in cyberattack | Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks... | CenterPoint Energy discloses customer data breach in SEC filing Re... | CenterPoint Energy confirms data breach after hacker claims 7.49M r... | CenterPoint Energy confirms data breach of customer personal inform... | CenterPoint Energy Breach Exposes 7.5M Records | CenterPoint Energy Form 8-K Breach Disclosure CyberSecureToday