CenterPoint Energy Investigates Potential Customer Data Breach Amid Multiple Proposed Class-Action Lawsuits

CenterPoint Energy serves roughly 7 million electricity and natural-gas customers across Indiana, Minnesota, Ohio and Texas.
A hacker claimed on a cybercrime forum on Sept. 12 to have obtained nearly 7.5 million records and offered a 2.5-gigabyte archive for download, warning that “next time we won’t simply pull data, we’ll start attacking the main infrastructure.” SecurityWeek said it could not verify the archive and noted that such claims are sometimes false or exaggerated.
The three lawsuits filed by Shamis and Gentile specifically identify CenterPoint’s guest bill-pay feature as a potential vulnerability, alleging that entering a valid account number could retrieve a large amount of personal information.
The lawsuits place the alleged breach between Aug. 17 and Sept. 1, though CenterPoint has not verified that the breach occurred. The filings include estimates ranging from about 6.7 million affected customers to 7 million leaked filtered records.
SecurityWeek reported that this was not the first public claim involving CenterPoint data: the company was among energy firms targeted by the access broker AntiBrok3rs in 2024, followed by another claim that the data may have originated from the Cl0p ransomware group’s 2023 MOVEit campaign.
CenterPoint Energy confirmed that an unauthorized third party accessed customer personal information through an external-facing system, according to SQ Magazine. A hacker claimed on a cybercrime forum on September 12 to have stolen nearly 7.5 million records and offered them for download, though SecurityWeek could not verify the archive and noted such claims are sometimes false or exaggerated.
The Houston utility, which serves roughly 7 million electricity and natural-gas customers across Indiana, Minnesota, Ohio and Texas, launched an investigation with outside cybersecurity experts and notified law enforcement, Technadu reported. Five proposed class-action lawsuits filed by customers allege millions of records including names, addresses, billing information and Social Security numbers may have been exposed.
On September 12, a threat actor posted on a cybercrime forum claiming to possess 7.49 million customer records from CenterPoint, according to SecurityWeek. The hacker offered a 2.5-gigabyte data archive for download and made an ominous warning: 'next time we won't simply pull data, we'll start attacking the main infrastructure.' However, SecurityWeek could not independently verify the archive's contents or authenticity.
Three class-action lawsuits filed by law firm Shamis and Gentile specifically pinpoint CenterPoint's guest bill-pay feature as a security weakness. The lawsuits allege that entering a valid account number could retrieve a large volume of personal information without additional authentication, giving hackers a direct pathway to customer data.
The proposed lawsuits accuse CenterPoint of maintaining inadequate security measures and failing to protect customer information. However, these remain proposed class actions—no class has been certified yet, and no court has ruled on the allegations.
CenterPoint has not independently verified when the breach occurred, but the lawsuits place it between August 17 and September 1. The legal filings estimate between 6.7 million and 7 million affected customers, though TS2 Tech noted the company has not officially confirmed the exact scope or types of exposed information.
This breach follows previous security incidents. SecurityWeek reported that CenterPoint was targeted by access broker AntiBrok3rs in 2024 and later faced another claim suggesting data may have originated from the Cl0p ransomware group's 2023 MOVEit campaign, indicating a pattern of vulnerability.
CenterPoint emphasized that electricity and natural-gas services to its 7 million customers remain fully operational and undisrupted by the breach, TEISS reported. The company is working with outside cybersecurity experts and law enforcement while taking protective measures to prevent future unauthorized access.
Publishers
17
Articles
71
Reach
88