Back to Blog
data breachutility billAPI securityidentity theftdocument privacy

7.49 Million Utility Records, Leaked One Account Number at a Time

A Houston utility's customer database walked out through a public API with no rate limiting and no auth. 7.49 million records, per the hacker. Your utility bill is the same document. Here's the part you can actually control.

By RedactID Team6 min read

Here is the detail that should bother you most, and it is not the breach itself. It is how the data left.

CenterPoint Energy is a Houston-based public utility. It supplies electricity and natural gas to roughly seven million accounts across Indiana, Minnesota, Ohio, and Texas, employs about 8,300 people, and clears over $9.3 billion in annual revenue. This is not a scrappy startup with a side project. This is a regulated critical-infrastructure operator with the budget to staff an entire security team.

And its customer database still walked out the door through a public API.

What actually happened

On September 14, CenterPoint filed an eight-K with the U.S. Securities and Exchange Commission and confirmed, in the company's own words, that "an unauthorized third party obtained personal information relating to a portion of the Company's customers through one of the Company's external-facing systems." The investigation is still ongoing. The company has not named the actor, the number of affected customers, or the specific fields.

The number and the mechanics come from a threat actor posting under the alias "4d722e4d656f77," reported by BleepingComputer on September 15 and picked up by Help Net Security the next day. Per the actor, the data came out of a company-managed public API that had no web application firewall, no rate limiting, no authorization checks, and no authentication token. The actor said it pulled the data in JSONL format and then filtered it into CSV.

We are attributing that carefully on purpose. The "7.49 million" figure is the hacker's number. What CenterPoint has put its name on is the simpler, harder-to-argue-with fact: their customers' personal information was taken through one of their own systems. That is enough to be worried.

One ID at a time

This was not a database dump pulled in one clean exfiltration. It was enumeration. The actor describes iterating through millions of IDs on the public API, collecting one full record per account, and running the whole thing until something stopped it.

And the thing that stopped it was a CAPTCHA.

According to Help Net Security's read of the forum post, the CAPTCHA cut the pull short at 7.49 million lines. The actor wrote that without it, "we would have pulled 17.44 million data." Read that again. A one-time math check, the cheapest control in the book, is what stood between 7.49 million records and 17.44 million.

That is the whole story in one image: a regulated utility, a public endpoint, a script, and no rate limit. The sophistication of the attack was essentially zero. The value of what it got was enormous.

What was in the records

The actor's list, as reported by BleepingComputer and SecurityPointBreak: names, phone numbers, service and billing addresses, account numbers, premise IDs, billing amounts, due dates, autopay and paperless billing status, rate class, email addresses, driver's license numbers, and the last four of a Social Security number.

Stop and look at that list for a second. It is, field for field, the information that prints on the back of a utility bill. The same account number, the same meter ID, the same billing history, the same partial SSN that you have been photographing and emailing to banks and landlords and brokers for a decade.

The breach did not invent any of your exposure. It is a reminder of what a single bill already contains, and how easily a copy of it moves around.

The honest limit

We build a redaction tool, so the honest answer comes first: this was not a breach you could have redacted away. The data was stolen from the utility's own API. You had no upload button you forgot to click, no PDF you should have flattened. No tool on your side touches a server-side enumeration. We would be doing you a disservice to imply otherwise.

Here is what redaction does control, and it is not a small thing.

Every "proof of address" you have ever passed was a copy of that same bill, with that same account number and meter ID, sitting in someone else's inbox, drive, or vendor's retention folder. Banks, apartments, crypto exchanges, gyms, phone carriers, movers, brokers. Each one is a copy of the record that CenterPoint just proved it can lose. You cannot rate-limit the utility's API. You can decide which forty inboxes get a full, unredacted version of your bill and which get just the name, address, and date they actually need.

The account number is the key to the record. That is the whole lesson. When the record is keyed by a number that is enumerable over the public web, the number is not just an identifier, it is a credential. The fewer full copies of it you put in the world, the fewer of them that surface the next time something like this happens.

What to do

You cannot un-leak CenterPoint's database. You can tighten the side you own:

  • Redact before you send. For proof of address, most verifiers need your name, the service address, and a recent date. The account number, meter ID, and billing breakdown are not part of that check. Cover them.
  • Flatten, don't just box. A black rectangle in a photo app or a PDF annotation is often removable. A proper redaction replaces the underlying data so there is nothing left to reveal.
  • Count your copies. Every unredacted bill in a vendor's inbox is a copy you did not choose to keep. Redaction is the only way to stop adding to that pile.

We put this on our own blog because the lesson generalizes further than utilities. Any service that keys a record to a public, enumerable ID and leaves the endpoint wide open has the same hole. Your credit union's portal, your property manager's tenant app, your insurer's claim system. The pattern is boring and old. The data it ships is not.

The cheapest control is rate limiting. The cheapest control on your side is redacting the copy before it leaves your browser. One is on the company. The other is on you.

---

The bottom line

A $9.3 billion regulated utility lost 7.49 million customer records through an API with no rate limit, and a CAPTCHA is what stood in the way of 17.44 million. You cannot fix their endpoint. You can fix the copies you send, and you can keep the full account number, meter ID, and billing history out of the forty inboxes that only need your name, address, and date.

The record is keyed by a number you can stop repeating. That is the lever.

---

Related: Redact a utility bill online · Redact bank statements · Redact documents for landlords · Redact any document online

Redact a utility bill in your browser before you send it: try RedactID free. In-browser, nothing uploads, nothing is stored. For unlimited redactions, see our plans & pricing.

Everything runs in your browser. Your file is never uploaded.

Ready to Protect Your Privacy?

RedactID lets you redact sensitive information from documents without uploading them — everything is processed on your device.