Este sitio web fue traducido automáticamente. Para obtener más información, por favor haz clic aquí.
Updated
NEWYou can now listen to Fox News articles!

If you pay an electric or gas bill every month, you probably think about the amount due, not all the personal information sitting behind that account. But your utility company may have your home address, phone number, billing history and other details that can become very useful in the wrong hands. That is what makes the breach at CenterPoint Energy worth paying attention to, even if you have never been one of its customers.

CenterPoint says an unauthorized third party obtained personal information belonging to some customers through an external-facing system. A hacker, meanwhile, claims to have stolen 7.49 million customer records, including addresses, account numbers, billing information and partial Social Security numbers.

There is an important catch. CenterPoint has confirmed that customer information was stolen, but it has not confirmed the hacker's 7.49 million figure or the specific information the attacker says was taken. So, there are still plenty of questions about how big this breach really is. Here's what CenterPoint has confirmed, what the hacker is claiming and what you should watch for now.

NEW! 🩺 Free CyberGuy LIVE class: Get Better Healthcare With AI Saturday, September 26 at 11 a.m. ET / 8 a.m. PT

Kurt "CyberGuy" Knutsson will show you five practical ways AI can help you organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare smarter questions for your doctor. No technical experience is needed.

Save your free spot at CyberGuyLive.com.

Register and receive the replay and step-by-step guide afterward.

DMV BREACH CONFIRMED AS HACKERS CLAIM 200,000 RECORDS STOLEN

CenterPoint Energy trucks.

CenterPoint Energy is investigating a cybersecurity incident that exposed personal information belonging to some customers. (CenterPoint Energy)

CenterPoint Energy confirms customer data was stolen

CenterPoint Energy disclosed the incident in a Sept. 14 filing with the U.S. Securities and Exchange Commission. The Houston-based utility says it became aware of an online post from a third party claiming to possess a data set containing CenterPoint customer information.

CenterPoint then activated its cybersecurity incident response procedures and brought in outside cybersecurity experts. As the investigation progressed, the company determined that an unauthorized third party had obtained personal information belonging to some customers through one of its external-facing systems.

CenterPoint has not publicly said how many customers were affected. It also has not detailed which types of personal information were taken. The company says it plans to notify affected customers and regulators as required once it determines the scope of the incident.

CyberGuy reached out to CenterPoint Energy asking whether it could confirm the hacker's claim that 7.49 million records were stolen, what customer information was affected and whether a public API was involved. CenterPoint referred us to its SEC filing and provided this statement: "Our filing speaks for itself." The company did not provide additional details in response to our questions.

There is one piece of reassuring news for anyone who depends on CenterPoint for power or gas. The company says its electric and natural gas services continued operating normally during the incident. CenterPoint also says it currently does not expect the breach to have a material impact on its financial condition.

Hacker claims 7.49 million CenterPoint records were stolen

The bigger number comes from the attacker. A threat actor using the alias "4d722e4d656f77" told BleepingComputer that they obtained 7.49 million CenterPoint customer records.

According to the hacker, those records contain:

  • Names
  • Phone numbers
  • Service and billing addresses
  • CenterPoint account numbers
  • Billing amounts
  • Partial Social Security numbers

The attacker later leaked the data after claiming CenterPoint ignored their attempts to make contact. Again, CenterPoint has confirmed that customer information was stolen, but it has not independently confirmed this list of exposed data or the 7.49 million record count. Also, 7.49 million records does not necessarily mean 7.49 million individual people were affected. One person or household can potentially appear in more than one record. CenterPoint says it is still working to determine the actual scope.

Hacker says a public CenterPoint system allowed automated data access

The attacker's explanation of how the theft allegedly happened may be one of the most interesting parts of this breach. The hacker told BleepingComputer they accessed the information by repeatedly cycling through millions of IDs using a public CenterPoint API.

An API allows different software systems to exchange information. Companies use them constantly behind websites and apps. According to the attacker, CenterPoint's API lacked protections that could have slowed or blocked mass automated requests. The hacker specifically claimed there was no effective rate limiting or web application firewall protection against the activity. CenterPoint's SEC filing does not confirm that attack method.

What CenterPoint does confirm is that the unauthorized third party obtained information through an external-facing system. That means we should treat the API explanation as the attacker's account until the company or investigators provide more technical details.

Person typing code on their laptop.

CenterPoint says an unauthorized third party obtained customer personal information through one of the company’s external-facing systems. (Annette Riedl/picture alliance via Getty Images)

FOREIGN HACKERS BREACH TWO MORE US WATER UTILITIES, THREATEN SAFETY OF COLORADO RESIDENTS

Why stolen utility records can be valuable to scammers

A utility account may not seem as sensitive as a bank account. Yet it can hold exactly the kind of information a scammer wants before contacting you.

Think about how convincing this could sound: Someone calls and knows your name. They know your service address. They may know your CenterPoint account number or recent billing amount. Then they tell you there is a problem with your payment. That conversation can feel much more legitimate because the scammer already has information you would expect only the utility company to know.

Criminals can also combine information from one breach with details leaked somewhere else. A partial Social Security number, phone number or address may become more useful when paired with another stolen database. That is one reason I tell people to think about breaches as pieces of a much larger identity puzzle.

Stolen information can stick around for years. Criminals can save it, trade it and revisit it long after the original breach disappears from the news. You can read more about why last year's data breach can become this year's identity fraud.

Watch for fake CenterPoint calls, texts and emails

The immediate threat may not come from someone opening an account in your name. It could arrive as a text message. Once news of a breach becomes public, scammers can take advantage of the confusion even if they never obtained the stolen database themselves.

You could receive a message claiming CenterPoint needs you to "verify" your account after the breach. Another scammer might warn that your electricity will be disconnected unless you make an immediate payment. Be especially suspicious if someone creates urgency and then asks you to click a link, provide account information or move money.

If you receive a suspicious CenterPoint message, go directly to the company's official website or use the contact information printed on your bill. Avoid calling a number supplied in an unexpected message.

8 ways to protect yourself after the CenterPoint Energy breach

Whether you are a CenterPoint customer or simply wondering what you would do after your own utility provider suffered a breach, these steps can reduce your exposure.

1) Watch for an official CenterPoint breach notice

CenterPoint says it intends to notify affected customers as required. If you receive a notice, read it carefully. Look for exactly what information CenterPoint says was involved and whether the company offers credit monitoring or other assistance. Do not rely on a text message or social media post claiming you were affected.

2) Freeze your credit

If CenterPoint’s breach notice confirms that Social Security information was involved, consider placing a credit freeze with Equifax, Experian and TransUnion. A freeze can make it harder for someone to open new credit accounts in your name. It is free, and you can temporarily lift it when you legitimately need a lender to access your credit file. Keep in mind that a freeze cannot stop every kind of identity theft. Existing account takeovers and other fraud can happen without a new credit check.

3) Check your credit reports and financial accounts

Review your credit reports for accounts or inquiries you do not recognize. Then keep an eye on your bank accounts and credit cards for unfamiliar transactions. If something looks suspicious, contact the financial institution using the number on its official website, statement or the back of your card.

4) Secure your email and utility accounts

Your primary email account deserves extra attention because criminals can use it to reset passwords for other services. Use a strong, unique password and turn on two-factor authentication (2FA). Do the same for your utility account if the provider offers those protections. A password manager can create unique passwords so one stolen login does not give an attacker access to several accounts.

WATER CYBERATTACK HITS AT LEAST 7 STATES

An electric grid.

CenterPoint Energy says its electric and natural gas services remained operational and undisrupted during the cybersecurity incident. (Kurt "CyberGuy" Knutsson)

5) Treat utility shutoff threats as a red flag

A scammer may claim you owe money and threaten to disconnect your electricity or gas immediately. Do not let the urgency rush you into paying. Hang up and contact the utility yourself through its official website or the customer service number printed on your bill.

6) Use strong antivirus protection

A convincing breach-related email can still lead to a malicious website or malware download. Strong antivirus software can help detect phishing sites, malicious links and malware before they cause more trouble. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.

7) Reduce how much personal information is already online

Data brokers and people-search sites may already publish your phone number, address and other personal information. Removing that data will not erase information stolen in a breach. However, reducing publicly available information gives scammers fewer pieces they can use to build a detailed profile around leaked data. You can remove information manually or use a data removal service to handle recurring opt-out requests. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting CyberGuy.com.

8) Consider identity theft monitoring

Identity theft protection can monitor credit activity and alert you when certain personal information appears in places where it could signal trouble. These services cannot prevent every form of identity theft. However, alerts can help you spot suspicious activity earlier. If you discover that someone has actually used your identity, document what happened and begin the recovery process quickly. See my tips and best picks on Best Identity Theft Protection at CyberGuy.com.

Kurt's key takeaways

A utility account can reveal more about you than you might expect. Your address, billing details and account information can give scammers enough personal context to make a fake call, text or email sound legitimate. We still do not know the full scope of this breach. That uncertainty is another reason to stay alert rather than wait for every answer before taking precautions. Watch your accounts, consider freezing your credit if sensitive information was exposed and be skeptical of urgent utility messages. We often have little choice about who provides our power or gas, which makes protecting the information customers hand over especially important.

If a company provides an essential service you cannot realistically live without, should it face tougher requirements for protecting the personal information you have no choice but to give it? Let us know by writing to us at CyberGuy.com.

Sign up for my FREE CyberGuy Report

  • Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
  • For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
  • Plus, you'll get instant access to my Ultimate Scam Survival Guide free when you join.

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

Copyright 2026 CyberGuy.com. All rights reserved.