[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0k9l5ZzaGx7pYOimnTSldhCMVuixl4CUNQYAMqF1_2k":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"0562bc87-dbfb-449e-b400-77b3a627a2ca","centerpoint-energy-api-vulnerability-exposes-749-million-customer-records","fcd21353-1395-4804-8361-fa369e35dd55","CenterPoint Energy API Vulnerability Exposes 7.49 Million Customer Records","A threat actor exploited vulnerabilities in CenterPoint Energy's public-facing API to exfiltrate nearly 7.5 million customer records containing sensitive personal and financial data, including partial Social Security numbers. Public APIs are high-value attack surfaces that require rigorous security testing, rate limiting, and authentication controls — weaknesses in any of these layers can allow mass data harvesting at scale. The exposure of names, addresses, account numbers, and partial SSNs creates significant risk of identity theft and fraud for affected customers. This breach underscores that utilities and critical infrastructure operators handling large volumes of consumer PII must treat API security as a first-class concern, not an afterthought.","**Immediate actions:**\n- Conduct an emergency security audit of all public-facing APIs to identify and remediate authentication, authorization, and rate-limiting gaps.\n- Implement API gateway controls (e.g., throttling, anomaly detection) to prevent large-scale automated data exfiltration.\n- Notify affected customers promptly and offer credit monitoring services in line with breach notification obligations.\n\n**Long-term improvements:**\n- Adopt a formal API Security lifecycle program including regular penetration testing and OWASP API Security Top 10 assessments.\n- Apply data minimization principles so that APIs only expose the minimum fields necessary for each use case, masking sensitive values like SSNs by default.\n- Enforce strong authentication (OAuth 2.0, API keys with scoped permissions) and role-based access control on all API endpoints.\n\n**Detection measures:**\n- Deploy API-specific monitoring and SIEM rules to alert on abnormal query volumes, bulk data requests, or sequential record enumeration patterns.\n- Establish a baseline of normal API traffic and configure automated alerts for deviations that could indicate scraping or exfiltration activity.\n- Integrate API logs into a centralized logging platform with sufficient retention to support forensic investigations.",[12,13,14,15,16,17,18,19,20,21],"NIST SP 800-53: SI-10 (Information Input Validation)","NIST SP 800-53: AC-3 (Access Enforcement)","NIST SP 800-53: AU-12 (Audit Record Generation)","CIS Control 16: Application Software Security","CIS Control 13: Network Monitoring and Defense","CIS Control 3: Data Protection","OWASP API Security Top 10: API1 (Broken Object Level Authorization), API4 (Unrestricted Resource Consumption)","GDPR Article 32: Security of Processing","GDPR Article 33: Notification of Personal Data Breach","NIST CSF: Protect (PR.DS-1, PR.AC-4), Detect (DE.CM-7)","published","2026-09-15T18:20:59.711932+00:00","2026-09-15T18:20:59.434+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcenterpoint-energy-confirms-customer-data-stolen-in-cyberattack\u002F","centerpoint-energy-confirms-customer-data-stolen-in-cyberattack-17561f","CenterPoint Energy confirms customer data stolen in cyberattack",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]