Threat Intelligence Brief
Curated summary with source attribution
Source: houstonchronicle.com
Threat Risk: High
Victim: Utility Customers
Incident: Alleged data breach involving millions of customer records via a guest payment portal.
Impact: Exposure of sensitive PII, including Social Security numbers, for approximately 6.7 to 7 million individuals.
Attacker: Unidentified threat actors
Analysis: The alleged breach stems from a vulnerability in CenterPoint Energy’s guest bill pay feature, which reportedly allowed access to PII using only an account number. This design flaw potentially exposed Social Security numbers and billing details for up to 7 million customers. The incident highlights the risk of improper authorization controls in public-facing payment portals.
Recommendations: Audit all guest-facing payment portals for insecure direct object references (IDOR).; Implement stronger identity verification requirements for accessing account-specific information.; Review API endpoints to ensure account numbers cannot be used to scrape sensitive PII.
Source: Houston Chronicle
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source