INDIANA – Houston-based CenterPoint Energy, which provides natural gas and electricity services to millions of Hoosiers across Southwestern and Central Indiana, has officially confirmed a cyberattack involving customer personal data.

The disclosure follows public claims made by an online threat actor operating under the alias “4d722e4d656f77,” who claimed to have exfiltrated 7.49 million customer records.
In a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC), CenterPoint Energy confirmed that an unauthorized third party accessed personal information through an external-facing digital system.
While CenterPoint has not yet verified the exact number of impacted households, the alleged stolen database includes sensitive personal and financial details:
- Full customer names and phone numbers
- Service addresses and billing addresses
- Utility account numbers and billed amounts
- Partial Social Security numbers
CenterPoint Energy serves approximately 7 million metered electric and natural gas customers across Indiana, Minnesota, Ohio, and Texas. Because utility customers generally cannot withhold personal data from their sole service provider, the breach has raised heightened concerns regarding infrastructure data security.
According to reports from BleepingComputer, the hacker claimed the breach was executed between August 17 and September 1 by exploiting an unprotected public-facing Application Programming Interface (API). The threat actor alleged that the system lacked standard security controls—such as rate-limiting and Web Application Firewall (WAF) protection—allowing an automated script to cycle through millions of customer account IDs.
The breach has already sparked multiple proposed class-action lawsuits in federal court on behalf of affected rate-payers.
Utility Response and Next Steps
CenterPoint Energy reassured customers that the cyber incident caused no disruption to its electric or natural gas operations and is not expected to materially affect the company’s financial condition.
The utility confirmed it has activated incident response procedures, engaged independent cybersecurity firms, implemented security enhancements to its public systems, and notified federal regulators and law enforcement.
Once the full scope of the investigation is established, CenterPoint plans to send direct notifications to all impacted customers in accordance with state and federal laws.


