Overview
- In a Sept. 14 SEC filing CenterPoint said an unauthorized third party obtained personal information for a portion of its customers through an external-facing system and that the investigation is ongoing.
- CenterPoint said electric and gas services were not disrupted and it does not expect a material business impact while it has activated incident-response procedures and hired outside cybersecurity experts.
- A threat actor posted on a cybercrime forum on Sept. 12 claiming to have pulled roughly 7.49 million records from an API that lacked rate limiting, a web application firewall and authentication; independent reporters have not validated the leaked dataset.
- At least five proposed federal class-action suits have been filed in the Southern District of Texas alleging inadequate security and pointing to a guest bill-pay feature as a possible weak point.
- Customers should watch for company notifications because exposed details such as names, addresses, account numbers and partial Social Security numbers could be used in targeted phishing, account‑takeover or identity‑theft schemes.