Utility giant admits breach after alleged leak of 7.49 million customer records

CenterPoint Energy has confirmed that an unauthorized party accessed personal information of some customers through one of its external systems. The Houston-based utility said the incident did not affect its electric or gas services and that it is working with third-party experts to determine the scope. The company filed a disclosure with the SEC after a threat actor leaked data allegedly obtained by abusing a public API lacking rate limiting and other protections.
CenterPoint Energy, serving roughly seven million metered customers across four states, confirmed unauthorized access to personal data via an external system. The SEC filing omitted victim counts and data types, but a threat actor claimed to have leaked 7.49 million records, including names, addresses, and partial Social Security numbers. The alleged method exploited a public API lacking rate limiting and WAF protections.
The utility said electric and gas services were unaffected and the incident is not expected to materially impact finances. CenterPoint has hired third-party experts, notified law enforcement, and strengthened protections. The breach reportedly occurred between August 17 and September 1, and multiple proposed class-action lawsuits have already been filed in federal courts.
The exposure of names, addresses, and partial Social Security numbers could enable targeted phishing, identity theft, or financial fraud for millions of utility customers. Because CenterPoint is a critical infrastructure provider, this incident may erode public confidence in the security of essential services. It could also pressure regulators and other utilities to enforce stricter API security standards, potentially leading to broader industry-wide changes in how customer data is protected.