Particle.news
Download on the App Store

CenterPoint Energy Confirms Customer Data Exposure After Hacker Claims 7.49 Million Records

The company has launched a forensic review, notified regulators and faces proposed class actions as investigators work to verify how much data was taken.

Overview

  • In a Sept. 14 SEC filing CenterPoint said an unauthorized third party obtained personal information for a portion of its customers through an external-facing system and that the investigation is ongoing.
  • CenterPoint said electric and gas services were not disrupted and it does not expect a material business impact while it has activated incident-response procedures and hired outside cybersecurity experts.
  • A threat actor posted on a cybercrime forum on Sept. 12 claiming to have pulled roughly 7.49 million records from an API that lacked rate limiting, a web application firewall and authentication; independent reporters have not validated the leaked dataset.
  • At least five proposed federal class-action suits have been filed in the Southern District of Texas alleging inadequate security and pointing to a guest bill-pay feature as a possible weak point.
  • Customers should watch for company notifications because exposed details such as names, addresses, account numbers and partial Social Security numbers could be used in targeted phishing, account‑takeover or identity‑theft schemes.