THE TELL

7.49 million utility bills leaked because nobody put a lock on the door

A hacker says they didn't break into CenterPoint Energy. They just asked its public system for customer number 1, then 2, then 3 — millions of times, and nothing stopped them.

CenterPoint Energy, a Houston-based utility that sends electricity and gas bills to about 7 million metered customers in Indiana, Minnesota, Ohio and Texas, has confirmed that someone walked off with personal information about some of them. The company found out the way a lot of companies now find out: it saw a post online where a stranger bragged about having the data.

The stranger, using the alias 4d722e4d656f77, told BleepingComputer they had taken 7.49 million customer records — names, phone numbers, service and billing addresses, account numbers, billing amounts and partial Social Security numbers. Then they published the data, saying the company had ignored their messages and treated them as a joke.

What it means

Here is the part worth sitting with. According to the intruder, there was no clever hack. CenterPoint had a public-facing system — an API, which is just the doorway an app uses to fetch your account details — and it would answer requests one ID at a time. So they wrote a script that ran through millions of IDs in a row. The intruder says the system had no rate limiting (nothing to say "you're asking too fast, stop"), no web application firewall, and no other protection against automated access.

That's the digital equivalent of a filing cabinet in a hallway with the drawers unlocked.
Share this

It also explains why the leaked fields are so mundane and so useful at the same time. A name plus a service address plus an account number plus how much you owe is everything a convincing phone scam needs. Someone calls, knows your address, knows your last bill to the dollar, and says the power will be cut tonight unless you pay now. Partial Social Security numbers are the extra nudge: the caller reads back digits you assume only the utility has, and you stop doubting them.

In its filing with the U.S. Securities and Exchange Commission, CenterPoint confirms that an unauthorized third party obtained personal information relating to "a portion" of its customers through one of its external-facing systems. The filing does not name the attacker, does not give a number of affected customers, and does not say which types of data were taken. The company says electric and gas service was unaffected and that it does not believe the incident will materially affect its business or financial condition. Both things can be true at once: the lights stayed on, and the customer list left the building.

Who it matters to

Anyone who has ever had a utility account in Indiana, Minnesota, Ohio or Texas — including people who moved out years ago, because old service addresses are exactly what's in a billing system. And a second group that rarely gets mentioned: twenty-somethings who just signed their first lease and put the electricity in their own name for the first time. That single act created a record with their name, their address, their phone and the amount they owe every month — sitting in a database they will never see and did not choose. The most common way young people lose their first savings isn't a bad trade. It's a caller who already knows enough about them to sound official.

What's next

Two concrete things to watch. CenterPoint says it is still working with third-party experts to determine the scope of customers and personal information affected, and intends to notify affected customers and regulators as required by law — so the real number, which the SEC filing does not give, should arrive in those notification letters. And multiple proposed class actions have already been filed in federal courts by law firms representing potentially impacted customers, alleging the breach occurred between August 17 and September 1. Those filings will force dates and details into the open faster than any corporate statement. What the company has not said, and what nobody has confirmed publicly, is whether the unprotected API described by the attacker is the system named in the filing.

One detail to hold on to

The attacker's stated reason for publishing everything wasn't money. It was that the company ignored their messages and, in their words, treated them as a joke. We don't know if that's true — it's one side's claim. But it's a strange new fact of life: 7.49 million people's billing details may have gone public because someone in an inbox didn't reply.

Sources: Bleeping Computer, "CenterPoint Energy confirms customer data stolen in cyberattack" by Bill Toulas, September 15, 2026; CenterPoint Energy filing with the U.S. Securities and Exchange Commission as quoted therein.

Why we ran this7/10

7,49 млн записей клиентов коммунальной компании — имена, адреса, суммы счетов и части номеров соцстрахования — утекли через открытый API без элементарной защиты от перебора, и это уже вылилось в коллективные иски.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← A model needed a number it couldn't find…Next: The fake MRI results were the bait. CHOSEN… →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X