01Summary
On 1 September 2026 a user posting as "4d722e4d656f77" advertised 7.49 million raw (6.73 million deduplicated) CenterPoint customer records and claimed an external API lacked proper authentication and rate limiting. On 14 September CenterPoint filed a Form 8-K confirming that an unauthorised party accessed personal information through an external-facing system. It said the intrusion "did not touch the systems that control electricity or natural gas delivery" and was not expected to be material. The claimed data includes names, contact details, service addresses, account numbers, billing and payment status, driver's licence information and the last four digits of Social Security numbers. CenterPoint serves about 7 million customers in Texas, Indiana, Minnesota and Ohio.
02Technical analysis
- Attack vector
- External-facing system (claimed insecure API)
03Threat actor
Aliases
- 4d722e4d656f77
04Victims and impact
Countries affected
- United States
05Data exposed
Data types
- Names
- Phone numbers
- Email addresses
- Service addresses
- Account numbers
- Billing data
- Driver's licence information
- Partial SSNs
06Timeline
- 2026-09-01Actor advertises CenterPoint data on a forum.
- 2026-09-14CenterPoint files a Form 8-K confirming unauthorised access.
07On the record
The intrusion did not touch the systems that control electricity or natural gas delivery.
08Disclosure and media
Publishing organisations
- Tech Insider
10Field notes
- 01The attacker's handle is hex for "Mr.Meow".
11Sources
Official documents
- CenterPoint Energy Form 8-K (14 Sep 2026)
References
- [1]Tech Insider: https://tech-insider.org/centerpoint-energy-data-breach-7-49-million-records-2026/









