CenterPoint Energy disclosed that an attacker stole 7.49 million customer records, exposing names, phone numbers, addresses and partial SSNs after exploiting an unprotected public API.
CenterPoint Energy confirmed that a cyber‑attack resulted in the theft of 7.49 million customer records, exposing names, phone numbers, addresses and partial Social Security numbers.
How the breach occurred
The intrusion was traced to an unprotected public API that allowed the attacker to retrieve data without authentication. Security researchers noted that the API endpoint had been publicly accessible for months before the breach was detected.
Data exposed
The compromised information includes each affected customer’s full name, residential address, telephone number and the last four digits of their Social Security number. No financial account numbers or passwords were reported as part of the leak.
Company response
CenterPoint Energy said it has taken the vulnerable API offline, engaged third‑party forensic investigators and is notifying affected customers. The utility also pledged to offer free credit‑monitoring services for a year to those impacted.
- Disable the exposed API endpoint
- Conduct a comprehensive security audit of all public interfaces
- Enhance monitoring for anomalous data access patterns
- Provide affected customers with identity‑theft protection
We take the privacy of our customers very seriously and are working tirelessly to mitigate the impact of this incident.
The breach underscores the importance of securing public-facing APIs, especially for utilities that handle large volumes of personal data.
Comments
No comments yet.