Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » US Utility CenterPoint Energy Confirms Breach as Hacker Claims 6.7 Million Records Stolen

US Utility CenterPoint Energy Confirms Breach as Hacker Claims 6.7 Million Records Stolen

By:
Last updated:September 17, 2026
Human Written
  • A threat actor alias published technical details claiming the theft and leak of over 6.7 million CenterPoint Energy customer records.

  • The intruder reportedly harvested sensitive identity and billing data by enumerating customer account numbers through unprotected guest-facing APIs.

  • CenterPoint Energy filed regulatory disclosures confirming an external system breach while assuring customers that physical gas and electric services remain unaffected.

Hacker Claims 6 7 Million CenterPoint Energy Customer Records Stolen

A dark web forum actor operating under the handle Hex_4d722e4d656f77 has published technical context regarding an alleged breach of CenterPoint Energy. The hacker affirmed that they took around 6,734,894 customer records, which contain about 48.8 gigabytes of secret operational information.

CenterPoint Energy is a utility company in the US that caters to a huge number of customers who utilize services related to electricity as well as natural gas. This massive public data leak has raised severe identity theft concerns for affected utility accounts across regional service territories.

Details of Unprotected Guest API Exploitation Mechanics

The intruder released a comprehensive technical breakdown describing how they extracted sensitive customer information from external enterprise servers. According to forum postings, the actor targeted improperly secured guest-facing Application Programming Interface endpoints managed by the utility. The attacker exploited these public endpoints by systematically enumerating valid customer account numbers without triggering access rate limits.

Additionally, the hacker made use of an alternative verification process to capture more identity attributes related to the active utility profiles. The hacker carried out the automated data capture program across seven phases of IP address ranges spread in Texas and Minnesota. But during this process, internal security systems, including strict use of CAPTCHA, later prevented further automated capture of data.

Further, the hacker also uploaded a file claiming that it is the entire CenterPoint Energy data in a filtered format for open download. The file purportedly has full customer names, phone numbers currently in use, email addresses, service addresses, and billing information.

Along with these, the exposed data fields also contain billing amounts, rate class information, and AutoPay enrollment status details. It also contains driver’s license numbers and part of the Social Security number of customers.

Utility Files Regulatory Disclosures while Third-Party Verification Continues

In response to public data claims, CenterPoint Energy filed an official disclosure statement with federal regulatory authorities. According to the company, unauthorized third parties have gained access to customer personal data by using the externally-facing digital system of the company. Nevertheless, official investigators have not reported the total number of records or confirmed the contents of the whole dataset.

Meanwhile, corporate leadership reassured consumers that physical electric and natural gas delivery systems remain fully operational without disruption. The company immediately activated its internal cybersecurity incident response workflows to contain the intrusion and secure exposed endpoints. External forensic consultants are working alongside corporate IT teams to determine the exact scope of compromised user accounts.

Consequently, the utility company notified federal law enforcement agencies and relevant state regulatory commissions regarding the unauthorized access. The firm indicated that the security event is unlikely to cause a material financial impact on ongoing business operations. Despite corporate assurances, multiple federal class action lawsuits have already been filed by impacted utility consumers.

Growing Risks of API Exploitation in Modern Infrastructure Platforms

Security experts claim that the use of public APIs without authentication is a serious threat to the security infrastructure of major providers. Consistent with the facts, hackers often apply automated scrapers to run scans through sequential ID numbers on public web pages. The tools receive valuable information without detection unless the system limits excessive access or applies detection processes.

Moreover, the stolen records present an additional threat for both residential and corporate clients. The data make it possible for hackers to use the utility records to construct successful scams or identity theft.

Large-scale consumer data sales can create similar risks beyond individual breaches. In another recent case, a dark web seller claimed to be offering 153 million US consumer records for just $750, highlighting how cheaply stolen personal information can circulate in underground markets.

Further, criminals can utilize the exposed details to contact and trick customers by posing as representatives of a utility provider. Also, they may threaten to disconnect services and deceive victims into sending immediate payments to them. Thus, it is necessary for security teams of companies to establish and use strict access rules for all external software interfaces and customer portals.

Crucial Steps for Consumer Account Protection and Monitoring

Utility customers must perform their due diligence to protect personal identity information from possible misuse. One step is to regularly inspect personal credit files for unidentified inquiries or the opening of false accounts. The creation of a credit freeze at major credit bureaus also provides effective protection from identity fraud in the long run.

Utility account owners should also remain alert in regard to unsolicited text messages, calls, or emails requesting immediate payment. Authentic service providers do not request prompt payment by using gift cards, cryptocurrency transfers, or money transfer software. Customers should verify payment requests by logging directly into official utility web portals using verified bookmark links.

Security measures such as ensuring the use of strong passwords and multi-factor authentication should also be put in place. It is also unwise to use the same credentials for utility accounts and other services. Adopting the best password practices can help avoid losing sensitive information from accounts further after breaches happen.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.