TTO-2026-0917-132 · September 17, 2026 Data BreachUtility

CenterPoint Energy Confirms 7.49 Million Customer Records Stolen Through Unauthenticated Public API

centerpointenergy.com7.49 million records claimedUnprotected public API — no WAF, no rate limiting, no authNames / addresses / account numbers / partial SSNsSEC 8-K filed Sep 14Class actions filedThreat actor: 4d722e4d656f77

Summary

CenterPoint Energy, the Houston-based utility serving approximately 7 million customers across Texas, Indiana, Minnesota, and Ohio, has confirmed that an unauthorized third party obtained customer information through one of its external-facing systems. The company disclosed the breach in a Form 8-K filed with the U.S. Securities and Exchange Commission on September 14, 2026, after a threat actor using the alias 4d722e4d656f77 claimed on a cybercrime forum that 7.49 million customer records had been extracted from an unauthenticated public API lacking rate limiting, web application firewall protection, and authentication requirements. CenterPoint has confirmed that customer data was stolen but has not disclosed the number of affected customers, the specific data types, or when the breach occurred. Three class action lawsuits have been filed.

Timeline

DateEvent
Sep 1, 2026Threat actor 4d722e4d656f77 posts claim on open web alleging 7.49 million CenterPoint customer records extracted via unauthenticated API; provides sample data
Sep 14, 2026CenterPoint Energy files Form 8-K with the SEC confirming unauthorized third party obtained customer information through an external-facing system
Sep 15-17, 2026Full breach details reported; three class action lawsuits filed by Shamis and Gentile focusing on guest bill pay feature as alleged access point

What Happened

According to the threat actor, CenterPoint’s public-facing customer portal included an API that allowed account information to be retrieved by iterating through customer ID numbers. The API had no web application firewall, no rate limiting, no authentication token requirement, and no other automated control against mass enumeration. The attacker stated that a CAPTCHA interrupted the extraction at 7.49 million records; without it, 17.44 million records would have been reachable.

The extracted fields reportedly include customer names, phone numbers, service addresses, billing addresses, account numbers, premise IDs, billing amounts, payment due dates, autopay status, paperless billing status, rate class, email addresses, driver’s license numbers, and the last four digits of Social Security numbers. The last four digits of Social Security numbers combined with name, address, and account number constitute a meaningful identity theft risk even without the full SSN.

CenterPoint’s SEC filing is sparse: the company confirmed data was stolen but declined to name the number of affected customers, the categories of data, or the timeline. The company said its operations remain uninterrupted and that it is working with third-party cybersecurity experts.

Domain Intelligence

centerpointenergy.com — 63.26

centerpointenergy.com scores at 63.26, in the low-trust range. The score carries only a T6_V2_CANONICAL flag — no T5 flags whatsoever. The absence of T5 flags means the topology layer found no threat intelligence observations associated with centerpointenergy.com prior to this incident. CenterPoint Energy is the breached organization.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 17, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026