CenterPoint Energy Confirmed Data Breach of 7 Million
A threat actor accessed millions of records through an unsecured public API, prompting federal class-action lawsuits.
Updated on Sept. 27, 2026 in Cybersecurity

Live Poll
Do you trust your utility provider to keep your personal information secure from hackers?
CenterPoint Energy has confirmed that an unauthorized party accessed approximately 7.49 million customer records between August 17 and September 1, 2026. The utility company reported the breach to the Securities and Exchange Commission after a threat actor leaked the data.
Why it matters
The breach highlights the systemic risk posed by inadequate rate limiting on public-facing application programming interfaces (APIs). The incident has triggered federal class-action litigation and necessitated an investigation by third-party cybersecurity experts.
The attacker exploited a public API — a software interface that allows different applications to communicate — by iterating through customer ID numbers. This method bypassed standard rate limiting or firewall protections designed to block automated scraping.
The players
CenterPoint Energy
A Houston-based utility company that manages energy infrastructure and service delivery across several states.
4d722e4d656f77
The threat actor who claimed responsibility for the breach and leaked the stolen customer data.
The details
The breach occurred because the company's public API lacked sufficient rate limiting, a security control that restricts the number of requests a user can make to a server within a specific timeframe to prevent abuse. By cycling through sequential customer ID numbers, the attacker was able to scrape millions of records. After the utility failed to respond to messages from the threat actor, identified by the alias 4d722e4d656f77, the stolen data was leaked publicly.
Timeline
August 17 to September 1, 2026: The window in which the data breach occurred.
September 17, 2026: The official date the breach was reported.
September 27, 2026: The publication date of the news reporting on the incident.
The Tech Race
This incident follows the documented trend of automated scraping attacks targeting poorly secured public endpoints as categorized by the OWASP API Security Project. It serves as a reminder that securing data requires more than perimeter defenses; it demands rigorous rate limiting for all public-facing APIs.
CenterPoint Energy has committed to notifying all affected customers, though a specific timeline for these communications has not been released. Readers should monitor their accounts for suspicious activity and be vigilant against phishing attempts that may use the compromised information.
The takeaway
This breach underscores the critical need for robust API security protocols to protect PII stored by public utilities. Customers should wait for direct notification from the utility regarding specific data exposure before taking further action to protect their personal financial identities.
Further reading
For broader trends in infrastructure protection, see our coverage on Cybersecurity.
Source note: This article includes information reported by Computer Crime Research Center.
Live Poll
Do you trust your utility provider to keep your personal information secure from hackers?









