A Texas utility’s open API leaked 7.49 million customer records

CenterPoint Energy confirmed a breach after a hacker said a poorly defended API let him pull millions of customer lines in one go.

CSBadmin
2 Min Read

An API with no authentication, no rate limiting, and no firewall in front of it is the whole story behind a 7.49 million record leak at a Texas utility. CenterPoint Energy has now confirmed the breach in a filing with US regulators.

The Houston company delivers electricity and gas to roughly 7 million accounts across Texas, Indiana, Minnesota, and Ohio, and disclosed the incident in an SEC Form 8-K dated September 14.

How the data reportedly walked out

A forum post on September 12, written under the alias 4d722e4d656f77, described draining the records from a CenterPoint-managed API that lacked a web application firewall, throttling, certificate validation, and any token check. The actor said the pull arrived as JSONL and was later filtered to CSV, and that a CAPTCHA halted the run. Without it, the claim goes, 17.44 million records were available.

Names, phone numbers, service and billing addresses, account numbers, billing amounts, email addresses, driver’s license numbers, and the last four digits of Social Security numbers were all listed as exposed.

The filing itself is narrower. It does not confirm the figure, identify the actor, or enumerate the fields, and it says utility service continued without disruption. Several class action suits have followed, according to local reporting.

For defenders the takeaway writes itself — customer lookup endpoints need authentication, throttling, and monitoring before they quietly become bulk export tools.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.