A threat actor’s publication of 7.5 million customer records on an underground cybercrime forum has forced Houston-based public utility CenterPoint Energy to confirm a security incident affecting its systems. In an official disclosure to the U.S. Securities and Exchange Commission (SEC), the energy provider acknowledged that an unauthorized third party exfiltrated customer personal information through an external-facing system. While the utility maintains that core electric and natural gas distribution services remain unaffected, the incident highlights persistent perimeter exposure challenges facing critical infrastructure operators.
The CenterPoint Energy breach came to light after a hacker posted a 2.5 GB archive on September 12 containing stolen customer details. Alongside the data dump, the threat actor issued an explicit extortion threat aimed at forcing executive response, stating: “next time we won’t simply pull data, we’ll start attacking the main infrastructure.”
CenterPoint Energy delivers electricity and natural gas to approximately 7 million customers across Texas, Indiana, Minnesota, and Ohio. Following the forum post, the utility launched an internal investigation alongside third-party cybersecurity specialists. Although the company expects no material financial impact and asserts that operational delivery of energy services continues without interruption, the breach exposes millions of records containing sensitive personal identifiable information (PII).
Perimeter Exposure and the Exfiltration Vector
External-facing systems—ranging from customer billing portals and self-service web applications to edge network appliances and managed file transfer applications—represent the primary attack surface for utility IT networks. In modern energy enterprises, web applications frequently interface with backend databases to process payments, update service addresses, and manage customer accounts.
When these public-facing endpoints suffer from unpatched web application vulnerabilities, authentication bypasses, broken access controls, or zero-day exploits, threat actors can bypass traditional perimeter security. Once inside, exfiltrating database contents via SQL injection, API exploitation, or compromised administrative credentials allows malicious actors to quickly harvest gigabytes of structured customer data before detection mechanisms trigger an alert.
Evaluating the Threat to OT and Critical Infrastructure
The hacker’s explicit threat regarding “main infrastructure” underscores the ongoing operational concerns surrounding the convergence of Information Technology (IT) and Operational Technology (OT) networks. Public utilities rely on OT systems—such as Supervisory Control and Data Acquisition (SCADA) networks, industrial control systems (ICS), and smart grid distribution management systems—to regulate physical gas pipelines and electrical distribution.
In well-architected utility environments, strict network segmentation (often aligned with the Purdue Model) isolates public-facing web servers and corporate IT networks from sensitive OT enclaves. While cybercriminals frequently leverage threats against physical infrastructure to heighten panic and coerce ransom payments, cross-domain pivoting from an external customer-facing server into air-gapped or demilitarized zone (DMZ)-protected OT networks requires sophisticated industrial control protocol exploits and deep operational access. Nevertheless, even the theoretical risk of IT-to-OT lateral movement requires immediate, aggressive isolation of affected web infrastructure to ensure critical controls remain secure.
Context: Historical Targeting and Supply Chain Risks
This is not CenterPoint Energy’s first encounter with extortionists targeting customer information. Throughout 2023 and 2024, the utility was named by initial access brokers, including the group known as AntiBrok3rs, as well as other cybercrime forum actors attempting to monetize stolen datasets.
However, those earlier incidents stemmed primarily from third-party supply chain vulnerabilities—specifically the widespread Cl0p ransomware exploitation of the MOVEit Transfer zero-day vulnerability (CVE-2023-34362)—where data was stolen from third-party vendors rather than directly from CenterPoint’s environment. The recent SEC filing marks a critical shift: CenterPoint directly attributes this current intrusion to an vulnerability within “one of the Company’s external facing systems,” moving the issue from supply chain risk management directly back to perimeter asset management and internet-exposed system hardening.
Realistic Blast Radius and Mitigation Strategy
The blast radius of 7.5 million compromised records extends beyond immediate regulatory disclosures and compliance consequences for the utility. Stolen PII—which typically includes customer names, physical service addresses, account numbers, email addresses, and phone numbers—provides threat actors with high-fidelity telemetry for secondary attacks. Exposed utility customer data is frequently repackaged for targeted social engineering campaigns, credential stuffing attacks, and utility-themed phishing lures designed to steal financial credentials or facilitate identity theft.
Recommendations for Utility Operators and Customers
- Utility Perimeter Audit: Organizations operating public-facing utility portals must immediately audit and review logs across all external web applications, payment gateways, and APIs to identify exposed endpoints, unauthorized data transfers, or unpatched vulnerabilities.
- Verify IT/OT Segmentation: System administrators should confirm that strict firewall rules and network segmentation prevent any direct routing or administrative connections between external customer portals and internal OT/SCADA control networks.
- Customer Vigilance: Potentially affected customers across Texas, Indiana, Minnesota, and Ohio should remain vigilant against unsolicited communications, emails, or text messages claiming to be from CenterPoint Energy demanding immediate bill payment or personal information.
Related content
CenterPoint Energy Confirms Data Breach After Hacker Leaks 7.5M Records
Security NewsAustralian Energy Provider Origin Confirms Customer Data Breach
Security NewsAccenture Confirms Data Breach After Source Code and Credentials Stolen
Security NewsAccenture Faces Data Breach: 35GB of Source Code Allegedly Stolen
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call