CenterPoint Energy a confirmé dans un dépôt auprès de la SEC avoir subi une cyberattaque majeure ayant entraîné le vol et la publication des données de 7,49 millions de clients.
Houston-based energy infrastructure giant CenterPoint Energy—which delivers electricity and natural gas to roughly seven million customer accounts across Texas, Indiana, Minnesota, and Ohio—has disclosed a major cybersecurity incident in a formal regulatory filing with the U.S. Securities and Exchange Commission (SEC Form 8-K). The disclosure follows an announcement on a dark web cybercrime forum where a threat actor put a database containing 7.49 million stolen customer records up for sale.
According to CenterPoint's SEC filing, the company became aware in September 2026 of an online claim advertising customer records. Subsequent forensic investigations confirmed that an unauthorized third party successfully compromised one of the company's external-facing enterprise web systems. The intruder exfiltrated customer personally identifiable information (PII), including full names, service addresses, contact phone numbers, account identifiers, and billing and usage histories.
CenterPoint stated that its operational industrial control systems (ICS/SCADA) and energy transmission grids remained unimpacted, ensuring uninterrupted energy distribution. However, the leakage of over seven million verified customer accounts creates severe exposure to secondary phishing campaigns, credential stuffing, and identity fraud.
Critical infrastructure utilities remain prime targets for sophisticated cybercrime rings seeking high-value data repositories. The incident highlights the peril of legacy web interfaces and vulnerable API touchpoints connected to corporate backend databases.
Recommended Steps for Affected Customers and Consumers
- Heightened Alert for Impersonation Scams: Beware of incoming SMS messages or emails claiming to represent utility customer service demanding immediate settlement of overdue bills. Verify all requests directly via official billing channels.
- Initiate a Credit Freeze: Customers are strongly urged to place a security freeze with major credit reporting agencies to prevent unauthorized credit lines from being opened in their name.
- Enforce Password Updates and MFA: Update account credentials on the utility provider portal and activate robust Multi-Factor Authentication (MFA).
Guidance for Enterprise Security Teams in Critical Infrastructure
- External Attack Surface Remediation: Routinely catalog and scan all internet-facing web portals and API gateways for authentication bypasses and outdated libraries.
- Strict Micro-segmentation: Enforce Zero Trust architectural boundaries isolating customer-facing web services from corporate Active Directory environments and core operational technology.
Mesures recommandées pour les responsables de la sécurité informatique
- Déploiement immédiat des correctifs de sécurité fournis par l'éditeur.
- Surveillance proactive des journaux système et des flux réseau.