CenterPoint Energy confirms intruder helped themselves to customer information
- ID
- 24672
- Status
- summarized
- Published
- 15 Sep 2026, 10:14 PM
- Fetched
- 15 Sep 2026, 10:30 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/cyber-crime/2026/09/15/centerpoint-energy-confirms-intruder-helped-themselves-to-customer-information/5296523
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 2.0
- Created
- 15 Sep 2026, 10:31 PM
- Tags
- Audience
- developers
What happened
Texas utility CenterPoint Energy disclosed a breach via SEC Form 8-K after a cybercrime forum post claimed 7.49 million files were stolen from a poorly secured API. The alleged data includes customer names, contact details, billing data, move-in dates, driver's license info, and last four digits of SSNs. CenterPoint says electricity and gas services remain operational and does not expect material financial impact.
Why it matters
The breach vector—a poorly secured internet-facing API—is a concrete reminder to audit your own external APIs for authentication and authorization gaps, but this incident has no direct impact on Malaysian builders or infrastructure.
Discussion angle
How API security failures at utilities map to what Malaysian regulated industries (telco, banking, energy) should be testing for in their own external-facing systems.