CenterPoint Energy (US utility): SEC filing confirms customer personal data stolen via external-facing system
BleepingComputer (15 September 2026) reports Houston-based utility CenterPoint Energy confirmed in an SEC filing that an unauthorized third party obtained personal information for a portion of its customers through an external-facing system. A threat actor alias “4d722e4d656f77” told BleepingComputer they exfiltrated about 7.49 million customer records (names, phones, service/billing addresses, account numbers, billing amounts, partial SSNs) by iterating IDs on a public API alleged to lack rate limiting/WAF. CenterPoint says electric and gas services were not impacted and does not expect a material business effect; it activated IR, engaged third-party experts, hardened systems, and notified law enforcement/regulators. Class-action complaints filed in US federal courts allege the incident window was about 17 August–1 September 2026. Company has not publicly matched the actor’s record count or data-type claims in the SEC text cited by the wire. Primary wire: BleepingComputer; company confirmation: SEC filing as cited there.
- Product
- CenterPoint Energy customer-facing / external systems (public API per actor claim)
- Exploited in Australia?
- unknown
- Patch to
- Utility customers: monitor for phishing/identity misuse; CenterPoint says services unaffected — follow company notices for affected individuals
Primary: BleepingComputer — CenterPoint Energy confirms customer data stolen (15 Sep 2026) · Vendor: CenterPoint Energy (company site) · SecurityWeek — CenterPoint confirms breach after leak (15 Sep 2026)
