The claim: an attacker called "4d722e4d656f77" and 7.49 million records
Security reporter BleepingComputer published an online post in which a threat actor using the alias "4d722e4d656f77" said they had stolen 7.49 million customer records from CenterPoint Energy and then leaked the data. According to the attacker, the records contained names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers (SSNs). The intruder told BleepingComputer they leaked the data after claiming the company ignored their messages and treated them as a joke.
How the attacker said the data was taken: automated API abuse
In descriptions provided to BleepingComputer, the intruder said they exfiltrated the information by iterating through millions of IDs on a CenterPoint public API. The attacker claimed that the API lacked rate limiting, had no web application firewall (WAF) protection, and did not include other security measures intended to block automated access. That account frames the incident as large‑scale automated enumeration of records exposed by an external‑facing system.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhat CenterPoint Energy has confirmed — and what it has not
CenterPoint Energy, a Houston‑based public utility serving roughly 7 million metered customers across Indiana, Minnesota, Ohio, and Texas, confirmed in the SEC filing that "data was stolen" and that an unauthorized third party obtained personal information for a portion of its customers. The company did not name the threat actor, disclose the number of affected customers, or enumerate the specific types of compromised data in that filing. CenterPoint said its electric and gas services were not impacted and that it does not believe the incident will materially affect its business or financial condition.
Company response and legal fallout
CenterPoint has activated incident‑response procedures, hired third‑party cybersecurity experts, strengthened protections on its systems, and reported the incident to law enforcement and regulators, the company stated. Multiple lawsuits proposing class actions were already filed in federal courts by law firms representing potentially impacted customers; those suits allege the breach occurred between August 17 and September 1. In its SEC filing, CenterPoint said it is continuing to work with third‑party experts to determine the scope of customers and personal information affected and intends to notify affected customers and regulatory authorities as required by applicable law.
What this means for customers, technologists, and regulators
- Customers: CenterPoint has said it will notify affected customers as required by law; customers should expect outreach if they are determined to be in the affected portion. The company also stated it does not believe its electric and gas services were disrupted.
- Technologists and security teams: The incident centers on alleged shortcomings in an external‑facing API—specifically, a lack of rate limiting and WAF protections against automated access. Security teams at utilities and other enterprises will watch whether the forensic work confirms automated enumeration as the vector and whether remediation measures match those claims.
- Regulators and litigators: CenterPoint reported the incident to law enforcement and regulators and disclosed the breach in an SEC filing; that sequence has already been followed by proposed class actions in federal court alleging an August 17–September 1 window for the compromise. Regulators will track notifications to affected customers and any disclosures the company files as its investigation continues.
CenterPoint’s disclosure leaves two closely linked facts in plain view: an online claim of 7.49 million stolen records and the company’s confirmation that an unauthorized party accessed customer information, without reconciling the two publicly. The company says it has taken immediate defensive steps and has engaged outside experts, and it has signaled it will notify customers and regulators as the investigation defines the scope. For now, the central open questions are quantifiable and narrow: how many customers were affected, what exact fields were compromised, and whether the public claim of 7.49 million records matches the company's forensic findings and legal disclosures.




