Security4 publishers3 min readPublished
CenterPoint confirms a customer data theft it learned about from a dark web post
CenterPoint Energy's 8-K says an unauthorized party took customer personal information through an external-facing system. The person selling the file says it came out of a public API with no rate limiting.
The Watch · Security desk

What happened
- CenterPoint Energy told the SEC that an unauthorized third party obtained personal information relating to a portion of its customers through one of the company's external-facing systems.
- The disclosure followed a September 12 post on a cybercrime forum by an actor using the alias 4d722e4d656f77, who claimed roughly 7.49 million CenterPoint customer records.
- The actor put a 2.5 GB archive of the claimed data up for download on the forum.
- The filing confirms the theft without naming the threat actor, the number of affected customers or the categories of data taken, and says electric and gas delivery was unaffected.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The claimed field set is enough to pass a call center script or send a bill that reconciles: name, service and billing address, account number, billing amount and the last digits of a Social Security number.
- capability Enumeration of sequential IDs needs no exploit and no malware, so any self-service customer API without throttling is extractable with a script. Detection depends on traffic monitoring the actor says was absent here.
- cost Litigation and notification costs start before the victim list exists: outside counsel is already filing while outside forensics are still counting affected customers.
- contradiction The only technical account of the vulnerable component comes from the person selling the data, and no outlet has validated the archive.
The person selling the data describes enumeration, not intrusion. They told BleepingComputer the records came out by iterating through millions of IDs on CenterPoint's public API, which they said had no rate limiting, no web application firewall and no other controls against automated access [6]. On the forum the same actor wrote: "We obtained said data from an API they managed and controlled, which lacked proper WAF protection, rate limiting, certification protection, and no JWT/Auth token to pull said data." [7]
The utility has not corroborated any of that. A CenterPoint spokesperson declined to answer questions about the criminal post [4], and SecurityWeek said it could not confirm the validity of the archive [19]. The claimed fields are names, phone numbers, service and billing addresses, account numbers, billing amounts and partial Social Security numbers [9].
CenterPoint delivers electricity and gas to about 7 million metered customers in Indiana, Minnesota, Ohio and Texas [11]. The claim is 7.49 million lines at one user per line, roughly 490,000 more than the metered customer count, so the set is not one row per current account [1]. The actor also said the pull got capped part way through: "Mid the 7.49 million mark, they did an attempt to stop us dumping data, which, with a simple CAPTCHA key, in terms, we would have pulled 17.44 million data from said company." [8] By that count, 9.95 million records stayed behind whatever control got applied [2]. The post ends with a threat: "next time we won't simply pull data, we'll start attacking the main infrastructure" [18].
Proposed class actions filed in federal court allege the breach ran between August 17 and September 1 [15]. The forum post came on September 12, eleven days after the end of that alleged window [5][3]. The 8-K went in on Monday evening [1]. It opens by saying the company "became aware of an online post by a third party claiming to have obtained a data set containing certain of the Company's customer information" [16]. The actor told BleepingComputer that CenterPoint ignored their messages and treated them as a joke before the data was leaked [22].
CenterPoint has turned up in leak claims before. In 2024 it was one of several energy firms named by an access broker calling itself AntiBrok3rs, and a separate actor later claimed to hold company data. Both sets were believed to have come from Cl0p's 2023 MOVEit campaign and from a third party, not from CenterPoint's own systems [17]. This filing points at one of the company's own external-facing systems [2].
The company said electric and gas delivery was not affected and that it does not believe the incident will materially affect its business or financial condition [12]. It reported net income of $244 million in the second quarter [14] and said it will incur costs from the investigation [13]. It has activated incident response, hired third-party cybersecurity experts, strengthened protections on its systems and reported the incident to law enforcement and regulators [20]. On scope, the filing says CenterPoint "is continuing to work with third-party experts to determine the scope of customers and personal information affected by the incident and intends to notify affected customers and regulatory authorities as required by applicable law" [21].
What to watch
- Whether CenterPoint's customer notification letters and state regulator filings put a number anywhere near 7.49 million.
- Whether an amended 8-K names the external-facing system and the data categories after the third-party review closes.
- Whether anyone independently validates the 2.5 GB archive against CenterPoint account records.