- CenterPoint Energy confirmed that customer data was stolen in a cyberattack, including personal information of some customers such as names, phone numbers, addresses, account numbers, billed amounts, and partial Social Security numbers.
- The breach involved an external-facing system that allegedly lacked basic safeguards against automated collection, prompting multiple proposed class-action lawsuits and an ongoing investigation by CenterPoint Energy.
- CenterPoint Energy has activated incident-response procedures, hired cybersecurity experts, strengthened system protections, and notified regulators and law enforcement, with plans to notify affected customers and authorities once the scope of the breach is determined.
CenterPoint Energy has confirmed that customer data was stolen in a cyberattack, raising new concerns about how major utilities handle the personal information customers must provide to keep the power on and gas service running.
Here’s what to know
In an SEC filing cited by BleepingComputer, CenterPoint Energy said an unauthorized party obtained personal information related to some customers through one of the company’s internet-facing systems.
The person claiming responsibility, using the alias “4d722e4d656f77,” told BleepingComputer earlier this month that they took 7.49 million customer records. The alleged records include customer names, phone numbers, service and billing addresses, account numbers, billed amounts, and partial Social Security numbers. CenterPoint Energy is based in Houston and serves about 7 million metered customers in Indiana, Minnesota, Ohio, and Texas.
So far, CenterPoint Energy has not said how many customers were affected or provided a precise list of the exposed data. What it has confirmed is that customer information was taken and that the investigation is still ongoing.
CenterPoint also said the incident did not disrupt its electric or natural gas operations and that it does not expect the breach to materially affect its business or financial condition.
More background
The claim is that the information was obtained through a public-facing application programming interface, or API, that allegedly lacked basic safeguards against automated collection.
The threat actor said they gathered the records by cycling through millions of IDs, describing a system that allegedly lacked rate limiting, web application firewall protection, and other defenses. In its SEC filing, CenterPoint Energy said the breach involved an external-facing system.
Utility users typically do not have the option of withholding personal and billing information from their provider.
The incident has already prompted multiple proposed class-action lawsuits in federal court. BleepingComputer reported that law firms representing potentially affected customers say the breach happened between Aug. 17 and Sept. 1.
What’s being done?
CenterPoint Energy said it has activated its incident-response procedures, hired outside cybersecurity experts, strengthened protections on its systems, and notified regulators and law enforcement.
The company also said it will notify affected customers and the appropriate authorities once it determines the scope of the breach, as required by law.
As CenterPoint Energy said in its SEC filing: “While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external-facing systems.”
Get TCD’s free newsletters for easy tips, smart advice, and a chance to earn $5,000 toward home upgrades. To see more stories like this one, change your Google preferences here.