news.mlab.sh
Back to the feed
threat-intel

Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

Medium
Summary

CenterPoint Energy, a Texas utility, has confirmed a data breach resulting in the exposure of customer information. The incident follows previous claims of data theft and is linked to the MOVEit campaign and a threat actor operating through an access broker. Despite the breach, service delivery has not been disrupted, and the company is investigating the extent of the compromise.

CenterPoint Energy, a Houston-based utility serving customers across Texas, Indiana, Minnesota, and Ohio, has confirmed that a threat actor has gained access to customer personal information. The company’s disclosure comes after a hacker publicly claimed to have stolen millions of records on a cybercrime forum on September 12th.

According to the SEC filing, CenterPoint Energy is currently investigating the incident and has determined that an unauthorized third party accessed customer data via one of the company’s external-facing systems. The company stated that despite the breach, service delivery to customers remains unaffected and that they do not anticipate a significant material impact on operations.

This is not the first time CenterPoint Energy has been targeted. In 2024, the company was among several energy providers impacted by an access broker named AntiBrok3rs. Furthermore, a separate hacker claimed to have obtained the company’s data in a previous incident, with the stolen data believed to stem from the Cl0p ransomware group’s 2023 MOVEit campaign. Analysts now believe that the current data leak originated from a third party rather than a direct compromise of CenterPoint Energy’s internal systems.

SecurityWeek is unable to independently verify the validity of the leaked data, a common tactic employed by threat actors to inflate claims and create a sense of urgency.

Read the full article at SecurityWeek