← All articles

CenterPoint Energy breach traced to an external API with no authentication

Texas utility CenterPoint Energy confirmed that an unauthorized party obtained customer personal information through an external-facing system. A threat actor claimed on a cybercrime forum to have pulled about 7.49 million records, including names, addresses, account and billing details, and partial Social Security numbers, through a company API that lacked authentication, rate limiting, and web-application-firewall protection. CenterPoint confirmed the incident in a regulatory filing but not the record count, and said energy services were unaffected. It is a textbook example of an exposed API being scraped at scale: without authentication and throttling, a public endpoint hands attackers a bulk export of customer data. The investigation is ongoing.

Check
Inventory external-facing APIs and confirm each one enforces authentication, authorization, rate limiting, and monitoring, and test them for endpoints that return customer data to unauthenticated callers.
Affected
About 7.49 million CenterPoint customers, per the attacker's claim, whose personal, account, and partial Social Security data may have been scraped; unauthenticated, unthrottled external APIs let attackers bulk-export such data with ease.
Fix
Require authentication and rate limiting on every external API, put them behind a web application firewall, monitor for bulk or anomalous access, and treat customer-data endpoints as high-value assets to test.