CenterPoint Energy Discloses Data Breach as Hacker Claims 7.49 Million Customer Records Stolen Through Unprotected API
CenterPoint Energy disclosed a data breach after a hacker claimed 7.49 million customer records were pulled through an unprotected API, prompting SEC filing and class-action lawsuits.
On September 14, CenterPoint Energy filed an SEC Form 8-K disclosing that an unauthorized third party had accessed customer data through one of its external-facing systems. The company said it activated its cybersecurity incident response protocols, brought in third-party forensic experts, and reported the incident to law enforcement. Electricity and gas services were not affected. But the scope of what had already been taken by that point dwarfed the procedural language of the filing.
According to a claim posted on a hacking forum by a user operating under the alias 4d722e4d656f77, the breach was not a sophisticated intrusion. The attacker said CenterPoint had left an unauthenticated API exposed to the public internet — one that lacked rate-limiting and web application firewall protections — and that pulling data from it was simple enough to yield 7.49 million raw customer records. The exposed fields, as described in the same claim, included names, phone numbers, email addresses, billing details, driver license numbers, and the last four digits of Social Security numbers.
This is a data breach that would be alarming for any company. For a regulated utility whose customers have no choice about handing over their personal and financial information — you do not pick your gas provider the way you pick your email service — the implications are worse. A customer cannot decide not to share their billing details or Social Security digits with the company that sends them a monthly bill and holds a monopoly on heating their home.
The lawsuits arrived before the disclosure did. At least five proposed federal class-action suits were filed against CenterPoint between September 10 and 13, according to Hoodline — three to four days before the SEC filing — by law firms including Shamis and Gentile and Lippe and Associates. The complaints, filed in the window between the breach and the company’s public acknowledgment of it, allege that CenterPoint failed to maintain basic data security standards. The timeline is notable: plaintiffs’ attorneys identified and moved on the breach faster than the company disclosed it to regulators, suggesting either a leak in the incident-response chain or simply the public nature of a forum post that, if the hacker’s account is accurate, anyone could have read.
CenterPoint has not publicly confirmed or denied the 7.49-million-record figure, nor has it specified exactly what data fields were exposed. Its SEC filing described the breach in general terms — third-party access, customer information, external-facing system — and noted that its investigation was ongoing. For the roughly 7.5 million customers potentially affected, that ambiguity is the problem: they do not yet know whether their driver’s license number or their partial SSN was among the fields an unauthenticated endpoint returned to whoever asked.
The underlying issue is not exotic. Rate-limiting and basic firewall rules on public-facing APIs are among the most elementary security controls in modern IT — the kind of thing that shows up on a first-month checklist for anyone building consumer-facing infrastructure. That a utility serving millions of customers might have missed those controls on an endpoint that exposed sensitive personal data is the kind of failure that attracts both regulatory attention and class-action counsel, and in this case it attracted both on roughly the same timeline.