CenterPoint Energy has confirmed that an unauthorized third party obtained personal information belonging to some of its customers through an external-facing system, following a leak of data by a threat actor. The Houston-based utility, which provides electric and natural gas services across Indiana, Minnesota, Ohio, and Texas, disclosed the incident in a filing with the U.S. Securities and Exchange Commission. The company said its investigation is ongoing and that it is working with third-party experts to determine which customers and what personal information were affected.

The disclosure came after a threat actor using the alias "4d722e4d656f77" told BleepingComputer they had stolen 7.49 million customer records from the company. According to the intruder, the records included names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers. The threat actor leaked the data and claimed the company had ignored their messages and treated them as a joke.

The intruder said the data was exfiltrated by iterating through millions of IDs on CenterPoint's public API, which they described as lacking rate limiting, web application firewall protection, and other safeguards against automated access. CenterPoint's SEC filing does not name the threat actor, the number of affected customers, or the specific types of compromised data. The investigation began after the company discovered an online post from a threat actor claiming to have stolen the records.

CenterPoint Energy serves approximately 7 million metered customers and employs roughly 8,300 people, generating over $9.3 billion in annual revenue. In its filing, the company stated that an unauthorized third party obtained personal information relating to a portion of its customers through one of its external-facing systems. It said it intends to notify affected customers and regulatory authorities as required by applicable law.

The company said its electric and gas services were not impacted by the cyberattack, and it does not believe the incident will materially affect its business or financial condition. CenterPoint has activated its incident-response procedures, hired third-party cybersecurity experts, strengthened protections on its systems, and reported the incident to law enforcement and regulators.

Multiple lawsuits proposing class actions against the firm have already been filed in federal courts by law firms representing potentially impacted customers. Those suits allege the data breach occurred between August 17 and September 1. The filing does not specify how many customers may be covered by the litigation or where the cases were filed.

More cybersecurity news from TechManNews.