[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fl6wSUpjW5p9nUXBa6OR7H6mJeU_IaAtUzIvu9R1uciQ":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"08cbc42b-87e3-462c-9a4a-a4ed6f46efe3","centerpoint-energy-breach-exposes-75m-customer-records-via-external-facing-system","3a8a3d6e-f107-44e2-8b07-8f2b95d9975c","CenterPoint Energy Breach Exposes 7.5M Customer Records via External-Facing System","An unauthorized third party exploited an external-facing system at CenterPoint Energy to steal data on approximately 7.5 million customers, highlighting the significant risk posed by internet-exposed infrastructure in critical utility environments. The breach suggests inadequate hardening, access controls, or unpatched vulnerabilities on perimeter-facing assets — common attack vectors that threat actors actively scan for. Utilities and critical infrastructure operators are high-value targets because of the sensitivity of operational data and the large customer bases they serve. Failing to secure external systems not only endangers customer personal information but also risks regulatory penalties and erosion of public trust in essential services.","**Immediate actions:**\n- Conduct an emergency audit of all external-facing systems to identify exposed services, unpatched software, and misconfigured access controls.\n- Restrict access to external-facing systems using IP allowlisting, multi-factor authentication, and least-privilege principles.\n- Notify affected customers promptly and offer credit monitoring in compliance with applicable breach notification laws.\n\n**Long-term improvements:**\n- Implement a continuous attack surface management (ASM) program to discover and inventory all internet-facing assets in real time.\n- Enforce data minimization policies so that external systems only store or process the minimum customer data necessary for their function.\n- Conduct regular third-party penetration testing focused on perimeter and external-facing infrastructure.\n\n**Detection measures:**\n- Deploy a Web Application Firewall (WAF) and anomaly-based intrusion detection on all external-facing systems to flag unusual data exfiltration patterns.\n- Establish robust logging and SIEM alerting for large-volume data access or export events from customer databases.\n- Define and test an incident response playbook specifically for customer data breaches to reduce dwell time and response gaps.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"CIS Control 1 – Inventory and Control of Enterprise Assets","CIS Control 3 – Data Protection","CIS Control 7 – Continuous Vulnerability Management","CIS Control 12 – Network Infrastructure Management","NIST SP 800-53 AC-3 – Access Enforcement","NIST SP 800-53 RA-5 – Vulnerability Monitoring and Scanning","NIST SP 800-53 SI-3 – Malicious Code Protection","NIST Cybersecurity Framework PR.AC-3 – Remote Access Management","NIST Cybersecurity Framework DE.CM-1 – Network Monitoring","GDPR Article 32 – Security of Processing","GDPR Article 33 – Notification of a Personal Data Breach","NERC CIP-007 – Systems Security Management","NERC CIP-011 – Information Protection","published","2026-09-15T16:21:05.561962+00:00","2026-09-15T16:21:05.266+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fwww.securityweek.com\u002Ftexas-utility-centerpoint-energy-confirms-breach-after-hacker-leaks-data\u002F","texas-utility-centerpoint-energy-confirms-breach-after-hacker-leaks-data-d1bf0f","Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":40,"name":41,"slug":42,"description":43,"color":44},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":46,"name":47,"slug":48,"description":49,"color":50},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]