Find notable cyber news and cases, enriched with sources, timelines, and signals.

CenterPoint Energy hit by network compromise

Incident
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

CenterPoint Energy disclosed a customer data breach after an unauthorized third party obtained personal information through an external-facing system, putting a portion of customers at risk of misuse. The company said the compromise was still under investigation and that it had not identified an impact to its electric and gas services. CenterPoint also said it was working to determine the full scope of affected customers and data while notifying the appropriate parties.

Related Happenings

CenterPoint Energy customer data leak

Data Leak
H score33 First: 15.09.2026 19:40 Last: 15.09.2026 19:40 Sources 1

How related: Earlier this month, a threat actor using the alias “4d722e4d656f77” told BleepingComputer they stole from CenterPoint Energy 7.49 million customer records that include names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers (SSNs).

About this happening: CenterPoint Energy confirmed a breach after an attacker leaked allegedly stolen customer records, exposing personal and billing data for a large portion of its customer ba...

Timeline

  1. 15.09.2026 19:40 2 articles · 2h ago

    CenterPoint Energy confirms unauthorized access to customer personal information

    Initial Disclosure

    CenterPoint Energy disclosed that an unauthorized third party obtained personal information relating to a portion of its customers through one of its external-facing systems. A threat actor using the alias 4d722e4d656f77 claimed to have stolen 7.49 million customer records, said they exfiltrated the data by iterating through millions of IDs on CenterPoint’s public API, and alleged the API lacked rate limiting and WAF protection. CenterPoint said its electric and gas services were not impacted, activated incident-response procedures, hired third-party cybersecurity experts, strengthened protections, and reported the matter to law enforcement and regulators while working to determine the full scope and notify affected customers and authorities.

    Show sources