CenterPoint Energy has confirmed that customer personal information was stolen through an external-facing system after a hacker claimed to possess 7.49 million records.

CenterPoint Energy Confirms Customer Data Stolen in Cyberattack as Investigation Widens

The420 Web Correspondent
6 Min Read

US utility giant CenterPoint Energy has confirmed that customer personal information was stolen in a cyberattack after a threat actor claimed online to possess millions of records linked to the company.

CenterPoint disclosed the incident in a filing with the US Securities and Exchange Commission on September 14, saying an unauthorised third party accessed customer information through one of its external-facing systems.

The company has not yet disclosed the exact number of customers affected or the full categories of data exposed.

Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise

Threat actor claimed to hold 7.49 million records

The investigation began after CenterPoint became aware of an online post from a third party claiming to have obtained a dataset containing company customer information.

BleepingComputer reported that the attacker claimed the dataset contained around 7.49 million records.

CenterPoint has not confirmed that figure.

The company said its investigation has established that an unauthorised party did obtain personal information belonging to a portion of its customers, but the scope is still being determined.

That distinction matters because a threat actor’s record count can include duplicate entries, outdated information or multiple records belonging to the same customer.

Until the investigation is complete, it would be inaccurate to describe 7.49 million people as confirmed victims.

Attack came through an external-facing system

CenterPoint said the information was obtained through one of its external-facing systems.

That usually refers to systems designed to be reachable from outside the company’s internal network, such as customer portals, online applications or internet-accessible services.

The company has not publicly identified the exact system that was compromised or explained how the attacker gained access.

After learning of the breach claim, CenterPoint activated its cybersecurity incident-response procedures, brought in external cybersecurity specialists and took additional steps to protect its systems.

The investigation is continuing with law enforcement and regulatory authorities.

Electricity and gas services were not disrupted

The breach appears to have affected customer data rather than the company’s operational energy systems.

CenterPoint said delivery of electricity and natural gas remained fully operational and was not disrupted by the incident.

That is an important distinction for an energy company.

Cyberattacks against utilities can potentially create two very different risks: theft of customer information or disruption of operational technology that controls physical infrastructure.

Based on CenterPoint’s current disclosure, there is no indication that attackers disrupted power or gas delivery.

The company serves approximately seven million metered customers across Texas, Indiana, Minnesota and Ohio.

Exact personal data exposed is still unknown

CenterPoint has not yet published a complete list of the information stolen.

The company said it is working with outside experts to identify the affected customers and the categories of personal information involved.

Affected customers will be notified where required by law.

This stage of the investigation is important because different data creates different risks.

A breach involving only names and contact information may primarily increase phishing and impersonation risk.

If more sensitive information such as account numbers, identification details or financial records was exposed, the consequences could be more serious.

For now, there is not enough public evidence to state that any specific category of highly sensitive information was taken.

Stolen utility data can fuel convincing scams

Even basic utility-account information can be useful to cybercriminals.

A scammer who knows a victim’s name, address and energy provider can create a much more believable phishing message or phone call.

The criminal may claim that a bill is overdue, a meter needs replacing or service will be disconnected unless immediate payment is made.

Because the attacker already knows real customer information, the message can appear far more credible than a generic phishing attempt.

That makes post-breach social engineering one of the main risks CenterPoint customers should watch for.

Company says financial impact is not expected to be material

CenterPoint told investors that it has already incurred costs responding to the incident and expects additional expenses as the investigation continues.

However, the company currently does not believe the breach is reasonably likely to have a material impact on its financial condition or operating results.

It also said it maintains customary cybersecurity insurance, which it expects will offset some of the costs associated with the incident.

That assessment could change if the investigation uncovers a larger impact, significant regulatory penalties or litigation.

The company has already notified certain regulators and law-enforcement authorities.

What this means for you: If you are a CenterPoint customer, be cautious of unexpected calls, texts or emails referring to your real utility account or threatening immediate disconnection. Contact the company through its official website or phone number rather than using links or numbers sent in unsolicited messages.

The420 Insight: The most important unanswered question is not whether CenterPoint was breached — the company has now confirmed that. It is how much customer information was taken and whether the attacker’s claim of 7.49 million records is close to the real scale. Until that scope is known, the biggest immediate risk is targeted phishing built around genuine customer data.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected