CenterPoint Energy confirms hackers stole customer data through an exposed API
CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.

Why it matters
What this means for organisations holding critical data
CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.
What happened
CenterPoint Energy, one of the largest utility companies in the United States, has confirmed that an unauthorised third party obtained personal information belonging to some of its customers through one of the company's external facing systems.
The confirmation came in a filing with the US Securities and Exchange Commission on 14 September, days after a threat actor posted on a dark web forum claiming to have stolen 7.49 million CenterPoint files through a poorly secured API. According to The Register, the advertised data includes customer names and contact details, billing information, move in dates, driving licence information and the last four digits of Social Security numbers.
CenterPoint delivers electricity and natural gas to homes and businesses, employs roughly 8,800 people and operates around 48.3 billion dollars in assets. The company says its operations were not affected and continue as normal. It has activated its incident response protocols, brought in third party cyber security experts, notified law enforcement and regulators, and says it will inform affected customers as required by law. It has also warned investors that the incident has already incurred expenses, with more expected as the investigation continues.
The scale claimed by the criminals, 7.49 million files, has not been independently verified. But the company has confirmed the essential point: customer data left the building.
The front door nobody was watching
If the claim of a poorly secured API proves accurate, this will not be a story about an elite hacking crew defeating state of the art defences. It will be a story about a door that was left unlocked.
APIs are the connective tissue of modern business. They let systems talk to each other, and they are everywhere. They are also routinely treated as plumbing rather than as what they actually are: direct routes into your most sensitive data, reachable by anyone on the internet who cares to look.
I have lost count of the organisations that can tell me in detail how their perimeter is defended, but cannot tell me how many external facing interfaces they have, what data each one can reach, or when anyone last checked. The perimeter gets the budget and the attention. The quiet connections get neither.
Critical infrastructure is not just the grid
When we talk about protecting critical infrastructure, the conversation usually jumps straight to operational technology: the control systems, the substations, the physical network. CenterPoint says its operations were unaffected, and that matters. Nobody's lights went out.
But a utility is more than its grid. It is also decades of customer records: names, addresses, billing histories, identity documents. For a criminal, that dataset is a gift. It enables identity fraud, highly convincing phishing and targeted social engineering against millions of households, and it never expires. You cannot change your move in history or your billing record the way you change a password.
If your organisation holds data that would harm your customers for years if it were published, the question is not whether it sits behind a firewall. The question is whether it needs to be connected at all.
The question worth asking
Every external facing system in your estate should be able to answer three questions. What data can it reach? Who is watching it? And does the data behind it need to be there?
Where records must be retained for regulatory or operational reasons, Offline Secure Storage® keeps them on dedicated hardware that is physically disconnected when not in use. An exposed API cannot leak an archive it cannot reach, and a criminal forum cannot advertise what was never connected in the first place.
Audit every connection as if it were a door, because that is exactly what it is. And put your crown jewels somewhere the doors do not go.
Mark Fermor is the founder of Firevault.
Sources
How Firevault would handle this
Controls an auditor can physically verify
Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.






