CenterPoint Energy confirmed that customer information was stolen after a threat actor claiming the alias 4d722e4d656f77 said they took 7.49 million records. The alleged exposure includes names, phone numbers, addresses, account details, billed amounts and partial Social Security numbers. CenterPoint says operations were not disrupted, has engaged outside cybersecurity experts and notified regulators, while multiple proposed class-action lawsuits have already been filed. The company will notify affected customers once the investigation determines the breach's scope.
CenterPoint Confirms Data Breach After Hacker Claims 7.49M Customer Records Exposed

CenterPoint Energy has confirmed that customer data was removed in a cyberattack after a threat actor claimed to have taken 7.49 million records, renewing scrutiny of how large utilities protect the personal information required to provide electricity and natural gas service.
What Happened
In an SEC filing cited by BleepingComputer, CenterPoint said an unauthorized party obtained personal information tied to a portion of its customers from one of the company's internet-facing systems. The person claiming responsibility, using the alias "4d722e4d656f77," told BleepingComputer they obtained 7.49 million customer records. The alleged dataset reportedly includes customer names, phone numbers, service and billing addresses, account numbers, billed amounts and partial Social Security numbers.
How The Data Was Allegedly Accessed
The claimant said the data came from a public-facing application programming interface (API) that allegedly lacked basic protections against automated harvesting. The actor described cycling through millions of IDs and said the system lacked rate limiting, a web application firewall and other standard defenses. CenterPoint's SEC filing likewise describes the incident as involving an external-facing system.
Impact And Response
CenterPoint, based in Houston, serves roughly 7 million metered customers across Indiana, Minnesota, Ohio and Texas. The company says the incident did not interrupt electric or natural gas operations and that it does not expect the breach to materially affect its business or financial condition.
CenterPoint said it has activated incident-response procedures, engaged outside cybersecurity specialists, implemented additional protections, and notified regulators and law enforcement. The company also said it will inform affected customers and the appropriate authorities once it determines the full scope of the breach, as required by law.
Legal Fallout
The incident has prompted multiple proposed class-action lawsuits in federal court. According to reports from law firms representing potentially affected customers, the intrusion occurred between Aug. 17 and Sept. 1.
"While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company's customers through one of the Company's external-facing systems."
What Customers Should Do
CenterPoint has not yet provided a definitive count of affected customers or a complete list of exposed fields. Customers should monitor account statements, review credit and identity-monitoring options, and follow any direct guidance from CenterPoint once notifications are issued.
Help us improve.




























