CenterPoint Energy confirmed Monday, Sept. 14, that an unauthorized third party obtained personal information belonging to some of its customers.

The Houston-based utility, which provides electric and natural gas infrastructure to portions of The Woodlands, disclosed the breach in a Form 8-K filed with the U.S. Securities and Exchange Commission. CenterPoint said it learned in September of an online post claiming a third party had obtained a dataset of customer information.

The company has not said how many customers were affected or what types of personal data were taken. CenterPoint said it is still working with outside cybersecurity experts to determine the scope.

What the lawsuits allege

Five proposed class action lawsuits have already been filed against CenterPoint in the Southern District of Texas, according to the Houston Chronicle.

Two law firms represent customers from Texas, Indiana and Minnesota. Florida-based Shamis and Gentile filed three suits on behalf of Laurie Eirwin, Latoya Wyche and Christa Floyd. Dallas-based Lippe and Associates filed two on behalf of Joyce Curry and Nathaniel Sonia.

The lawsuits allege the breach occurred between Aug. 17 and Sept. 1. One suit claims roughly 7 million filtered records were leaked. Another estimates approximately 6.7 million customers were affected. No class has been certified in any of the cases.

Three of the suits single out CenterPoint's online guest bill pay feature as the alleged weak point. That feature lets customers pay a bill using only an account number but also retrieves personal information when the correct number is entered, according to the lawsuits.

What data may be at risk

CenterPoint itself has not confirmed what information was exposed. A threat actor using the alias "4d722e4d656f77" told BleepingComputer they obtained 7.49 million records. The threat actor claimed the data includes names, phone numbers, service and billing addresses, account numbers, billing amounts and partial Social Security numbers.

The threat actor said the data was pulled by exploiting a public-facing API, a software connection point that links systems, which allegedly lacked basic security protections. Those claims have not been independently verified.

A separate law firm investigation notice listed similar categories of potentially compromised data, adding premise IDs, payment status, autopay and paperless billing status, according to a press release from Edelson Lechtzin LLP.

CenterPoint's response

CenterPoint said it activated cybersecurity response protocols, launched an investigation with third-party experts and took steps to protect its systems. The company reported the incident to law enforcement and regulatory agencies.

Electric and natural gas service has not been disrupted, the company said. CenterPoint added that it carries cybersecurity insurance it believes will offset related costs, according to a Reuters report carried by Channel News Asia.

A CenterPoint spokesperson told KPRC 2, "Our filing speaks for itself."

What Woodlands residents should know

CenterPoint provides the electric and natural gas grid for portions of The Woodlands, according to The Woodlands Township. Even residents who pay a separate retail electricity provider may have account data with CenterPoint as the transmission and distribution utility.

The company said it plans to notify affected customers as required by law but has not announced a timeline. Residents who suspect their information may have been compromised can place a fraud alert with the three major credit bureaus or freeze their credit at no cost.