如果你每月都要缴纳电费或燃气费,你可能只会关注应付金额,而不会在意账户背后的各项个人信息。但你的公用事业公司可能掌握着你的家庭住址、电话号码、缴费记录及其他信息,一旦落入不当之手,这些信息可能会被大加利用。正因如此,CenterPoint Energy 发生的数据泄露事件值得关注,即使你从来不是它的客户。
If you pay an electric or gas bill every month, you probably think about the amount due, not all the personal information sitting behind that account. But your utility company may have your home address, phone number, billing history and other details that can become very useful in the wrong hands. That is what makes the breach at CenterPoint Energy worth paying attention to, even if you have never been one of its customers.
CenterPoint 表示,一个未经授权的第三方通过对外系统获取了部分客户的个人信息。与此同时,一名黑客声称窃取了749万条客户记录,包括地址、账户号码、账单信息以及部分社会安全号码。
CenterPoint says an unauthorized third party obtained personal information belonging to some customers through an external-facing system. A hacker, meanwhile, claims to have stolen 7.49 million customer records, including addresses, account numbers, billing information and partial Social Security numbers.
有一个关键问题需要注意。CenterPoint 已确认客户信息被盗,但尚未证实黑客所说的749万这一数字,也未证实攻击者声称窃取的具体信息。因此,这次数据泄露事件的实际规模仍有很多疑问。下面将梳理 CenterPoint 已确认的信息、黑客的说法,以及你目前应该关注的事项。
There is an important catch. CenterPoint has confirmed that customer information was stolen, but it has not confirmed the hacker's 7.49 million figure or the specific information the attacker says was taken. So, there are still plenty of questions about how big this breach really is. Here's what CenterPoint has confirmed, what the hacker is claiming and what you should watch for now.
全新上线!🩺 免费 CyberGuy 直播课:用人工智能改善医疗保健。9月26日周六,美国东部时间上午11点/太平洋时间上午8点,库尔特·“CyberGuy”·克努特森将介绍五种实用方法,展示人工智能如何帮助你整理病史、记住重要预约的详细信息、理解复杂的医疗信息、查询处方药,以及为医生准备更有深度的问题。无需任何技术经验。
NEW! 🩺 Free CyberGuy LIVE class: Get Better Healthcare With AI Saturday, September 26 at 11 a.m. ET / 8 a.m. PT Kurt "CyberGuy" Knutsson will show you five practical ways AI can help you organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare smarter questions for your doctor. No technical experience is needed.
前往 CyberGuyLive.com 免费报名,课后即可获取回放和分步指南。
Save your free spot at CyberGuyLive.com and receive the replay and step-by-step guide afterward.
车管局(DMV)数据泄露已获证实,黑客声称20万条记录被盗。CenterPoint Energy 在9月14日提交给美国证券和交易委员会的一份文件中披露了此事。这家总部位于休斯敦的公用事业公司表示,公司获悉第三方在网上发布了一则帖子,声称掌握着一份包含 CenterPoint 客户信息的数据集。
DMV BREACH CONFIRMED AS HACKERS CLAIM 200,000 RECORDS STOLEN CenterPoint Energy disclosed the incident in a Sept. 14 filing with the U.S. Securities and Exchange Commission. The Houston-based utility says it became aware of an online post from a third party claiming to possess a data set containing CenterPoint customer information.
CenterPoint随后启动了网络安全事件响应流程,并引入了外部网络安全专家。随着调查推进,公司确定,未经授权的第三方通过其某个对外开放的系统获取了部分客户的个人信息。
CenterPoint then activated its cybersecurity incident response procedures and brought in outside cybersecurity experts. As the investigation progressed, the company determined that an unauthorized third party had obtained personal information belonging to some customers through one of its external-facing systems.
CenterPoint尚未公开说明有多少客户受到影响,也未详细说明哪些类型的个人信息被窃取。公司表示,一旦确定事件的影响范围,将按照相关要求通知受影响的客户和监管机构。
CenterPoint has not publicly said how many customers were affected. It also has not detailed which types of personal information were taken. The company says it plans to notify affected customers and regulators as required once it determines the scope of the incident.
CyberGuy联系了CenterPoint Energy,询问该公司能否确认黑客关于749万条记录被盗的说法、哪些客户信息受到影响,以及此次事件是否涉及公共API。CenterPoint让我们参阅其向美国证券交易委员会(SEC)提交的备案文件,并提供了这份声明:“我们的备案文件足以说明一切。”面对我们的提问,该公司没有提供更多细节。
CyberGuy reached out to CenterPoint Energy asking whether it could confirm the hacker's claim that 7.49 million records were stolen, what customer information was affected and whether a public API was involved. CenterPoint referred us to its SEC filing and provided this statement: "Our filing speaks for itself." The company did not provide additional details in response to our questions.
对于依赖CenterPoint供应电力或燃气的用户而言,有一条令人安心的消息。公司表示,事件发生期间,其电力和天然气服务仍正常运行。CenterPoint还表示,目前预计此次数据泄露不会对其财务状况产生重大影响。
There is one piece of reassuring news for anyone who depends on CenterPoint for power or gas. The company says its electric and natural gas services continued operating normally during the incident. CenterPoint also says it currently does not expect the breach to have a material impact on its financial condition. The bigger number comes from the attacker. A threat actor using the alias "4d722e4d656f77" told BleepingComputer that they obtained 7.49 million CenterPoint customer records.
更大的数字则来自攻击者。一名使用别名“4d722e4d656f77”的威胁行为者向BleepingComputer表示,他们获取了749万条CenterPoint客户记录。据该黑客称,这些记录包含:后来,攻击者公开泄露了这些数据,并声称CenterPoint无视了其试图联系对方的努力。CenterPoint已经确认客户信息遭窃,但尚未独立证实这份暴露数据清单或749万条记录这一数字。此外,749万条记录不一定意味着有749万名不同的人受到影响。同一个人或同一个家庭可能出现在多条记录中。CenterPoint表示,仍在确定此次事件的实际影响范围。
According to the hacker, those records contain: The attacker later leaked the data after claiming CenterPoint ignored their attempts to make contact. Again, CenterPoint has confirmed that customer information was stolen, but it has not independently confirmed this list of exposed data or the 7.49 million record count. Also, 7.49 million records does not necessarily mean 7.49 million individual people were affected. One person or household can potentially appear in more than one record. CenterPoint says it is still working to determine the actual scope. The attacker's explanation of how the theft allegedly happened may be one of the most interesting parts of this breach. The hacker told BleepingComputer they accessed the information by repeatedly cycling through millions of IDs using a public CenterPoint API.
攻击者对据称发生的窃取行为的解释,可能是这起数据泄露事件中最值得关注的环节之一。这名黑客向BleepingComputer表示,他们利用CenterPoint面向公众开放的API,反复遍历数百万个ID,获取了相关信息。
An API allows different software systems to exchange information. Companies use them constantly behind websites and apps. According to the attacker, CenterPoint's API lacked protections that could have slowed or blocked mass automated requests. The hacker specifically claimed there was no effective rate limiting or web application firewall protection against the activity. CenterPoint's SEC filing does not confirm that attack method.
API可以让不同的软件系统交换信息。公司经常在网站和应用程序后台使用API。据该攻击者称,CenterPoint的API缺少能够减缓或阻止大规模自动化请求的保护措施。这名黑客尤其声称,当时没有有效的速率限制,也没有Web应用防火墙来阻止相关活动。CenterPoint向美国证券交易委员会提交的文件并未确认这种攻击方式。
What CenterPoint does confirm is that the unauthorized third party obtained information through an external-facing system. That means we should treat the API explanation as the attacker's account until the company or investigators provide more technical details.
CenterPoint确实确认的是,未经授权的第三方通过一个面向外部的系统获取了信息。这意味着,在公司或调查人员披露更多技术细节之前,我们应当将有关API的解释视为攻击者的单方面说法。
FOREIGN HACKERS BREACH TWO MORE US WATER UTILITIES, THREATEN SAFETY OF COLORADO RESIDENTS A utility account may not seem as sensitive as a bank account. Yet it can hold exactly the kind of information a scammer wants before contacting you.
外国黑客攻破美国另外两家供水公司,危及科罗拉多州居民安全 公用事业账户的敏感程度可能不如银行账户,但其中可能恰好包含骗子在联系你之前想要获取的信息。
Think about how convincing this could sound: Someone calls and knows your name. They know your service address. They may know your CenterPoint account number or recent billing amount. Then they tell you there is a problem with your payment. That conversation can feel much more legitimate because the scammer already has information you would expect only the utility company to know.
试想一下这听起来会有多逼真:有人打电话来,不仅知道你的名字,还知道你的服务地址。他们甚至可能知道你的CenterPoint账户号码或最近的账单金额。然后他们告诉你,你的付款出了问题。由于骗子已经掌握了你认为只有公用事业公司才知道的信息,这样的对话会让人感觉合法得多。
Criminals can also combine information from one breach with details leaked somewhere else. A partial Social Security number, phone number or address may become more useful when paired with another stolen database. That is one reason I tell people to think about breaches as pieces of a much larger identity puzzle.
罪犯还可以将一次泄露的信息与在其他地方泄漏的细节结合起来。当部分社会安全号码、电话号码或地址与另一个被盗数据库配对时,可能会变得更有用。这就是为什么我告诉人们,应该把数据泄露看作是更大规模身份拼图中的碎片。
Stolen information can stick around for years. Criminals can save it, trade it and revisit it long after the original breach disappears from the news. You canabout why last year's data breach can become this year's identity fraud.
被盗信息可能会持续存在多年。在最初的数据泄露从新闻中消失很久之后,罪犯仍然可以保存、交易并重新利用这些信息。你可以思考为什么去年的数据泄露会变成今年的身份欺诈。
The immediate threat may not come from someone opening an account in your name. It could arrive as a text message. Once news of a breach becomes public, scammers can take advantage of the confusion even if they never obtained the stolen database themselves.
直接的威胁可能不是来自有人以你的名义开立账户。它可能会以短信的形式出现。一旦数据泄露的消息公之于众,即使骗子自己从未获取被盗数据库,他们也可以利用这种混乱进行诈骗。
You could receive a message claiming CenterPoint needs you to "verify" your account after the breach. Another scammer might warn that your electricity will be disconnected unless you make an immediate payment. Be especially suspicious if someone creates urgency and then asks you to click a link, provide account information or move money.
你可能会收到一条信息,声称CenterPoint需要你在数据泄露后“验证”你的账户。另一个骗子可能会警告说,除非你立即付款,否则你的电力将被切断。如果有人制造紧迫感,然后要求你点击链接、提供账户信息或转账,请务必格外警惕。
If you receive a suspicious CenterPoint message, go directly to the company's official website or use the contact information printed on your bill. Avoid calling a number supplied in an unexpected message.
如果你收到可疑的CenterPoint信息,请直接访问该公司官方网站或使用账单上印刷的联系方式。避免拨打意料之外的信息中提供的电话号码。
Whether you are a CenterPoint customer or simply wondering what you would do after your own utility provider suffered a breach, these steps can reduce your exposure.
无论你是CenterPoint的客户,还是只是在思考如果自己的公用事业供应商遭遇泄露你会怎么做,这些步骤都可以减少你的风险。
CenterPoint says it intends to notify affected customers as required. If you receive a notice, read it carefully. Look for exactly what information CenterPoint says was involved and whether the company offers credit monitoring or other assistance. Do not rely on a text message or social media post claiming you were affected.
CenterPoint表示,它打算按要求通知受影响的客户。如果您收到通知,请仔细阅读。查看CenterPoint具体说明涉及哪些信息,以及公司是否提供信用监控或其他援助。不要依赖声称您受影响的短信或社交媒体帖子。
CenterPoint says it intends to notify affected customers as required. If you receive a notice, read it carefully. Look for exactly what information CenterPoint says was involved and whether the company offers credit monitoring or other assistance. Do not rely on a text message or social media post claiming you were affected.
如果CenterPoint的违规通知确认涉及社会安全号码信息,请考虑向Equifax、Experian和TransUnion申请信用冻结。冻结可以使他人更难以您的名义开设新的信用账户。这是免费的,当您确实需要贷款机构访问您的信用档案时,可以暂时解除冻结。请记住,冻结无法阻止所有类型的身份盗窃。现有账户被接管和其他欺诈行为可能在无需新信用检查的情况下发生。
If CenterPoint’s breach notice confirms that Social Security information was involved, consider placing a credit freeze with Equifax, Experian and TransUnion. A freeze can make it harder for someone to open new credit accounts in your name. It is free, and you can temporarily lift it when you legitimately need a lender to access your credit file. Keep in mind that a freeze cannot stop every kind of identity theft. Existing account takeovers and other fraud can happen without a new credit check. Review your credit reports for accounts or inquiries you do not recognize. Then keep an eye on your bank accounts and credit cards for unfamiliar transactions. If something looks suspicious, contact the financial institution using the number on its official website, statement or the back of your card.
检查您的信用报告,查看是否有您不认识的账户或查询记录。然后留意您的银行账户和信用卡,查看是否有陌生交易。如果发现可疑情况,请使用其官方网站、账单或卡背面的电话号码联系金融机构。
Review your credit reports for accounts or inquiries you do not recognize. Then keep an eye on your bank accounts and credit cards for unfamiliar transactions. If something looks suspicious, contact the financial institution using the number on its official website, statement or the back of your card.
您的主要电子邮件账户值得额外关注,因为犯罪分子可以利用它重置其他服务的密码。使用强且唯一的密码,并开启双因素认证(2FA)。如果服务商提供这些保护措施,请对您的公用事业账户做同样的设置。密码管理器可以创建唯一密码,这样一个密码被盗不会让攻击者访问多个账户。
Your primary email account deserves extra attention because criminals can use it to reset passwords for other services. Use a strong, unique password and turn on two-factor authentication (2FA). Do the same for your utility account if the provider offers those protections. A password manager can create unique passwords so one stolen does not give an attacker access to several accounts.
水务网络攻击波及至少7个州 诈骗者可能声称您欠款,并威胁立即切断您的电力或燃气。不要让紧迫感冲昏头脑而匆忙付款。挂断电话,通过其官方网站或账单上印刷的客服电话自行联系公用事业公司。
WATER CYBERATTACK HITS AT LEAST 7 STATES A scammer may claim you owe money and threaten to disconnect your electricity or gas immediately. Do not let the urgency rush you into paying. Hang up and contact the utility yourself through its official website or the customer service number printed on your bill.
一封看似真实的与数据泄露相关的电子邮件,仍可能将您引导至恶意网站或诱导您下载恶意软件。强大的杀毒软件可帮助在钓鱼网站、恶意链接和恶意软件造成更大麻烦之前将其检测出来。请访问 CyberGuy.com 查看我为您的 Windows、Mac、Android 和 iOS 设备推荐的 2026 年最佳杀毒保护软件。
A convincing breach-related email can still lead to a malicious website or malware download. Strong antivirus software can help detect phishing sites, malicious links and malware before they cause more trouble. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android and iOS devices at CyberGuy.com.
数据经纪商和人员搜索网站可能已经发布了您的电话号码、地址和其他个人信息。删除这些数据无法抹去泄露事件中被盗的信息。不过,减少公开可获取的信息,会让骗子用于结合泄露数据构建详细档案的素材变少。您可以手动删除信息,也可使用数据删除服务来处理定期的选择退出请求。请访问 CyberGuy.com 查看我推荐的顶级数据删除服务,并获取免费扫描,了解您的个人信息是否已在网络上泄露。
Data brokers and people-search sites may already publish your phone number, address and other personal information. Removing that data will not erase information stolen in a breach. However, reducing publicly available information gives scammers fewer pieces they can use to build a detailed profile around leaked data. You can remove information manually or use a data removal service to handle recurring opt-out requests. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting CyberGuy.com.
身份盗窃保护服务可监控信贷活动,并在特定个人信息出现在可能预示麻烦的地方时向您发出警报。这些服务无法防范所有形式的身份盗窃。不过,警报能帮助您更早地发现可疑活动。如果您发现有人确实冒用了您的身份,请记录发生的情况并尽快启动恢复流程。请访问 CyberGuy.com 查看我的建议和最佳身份盗窃保护推荐。
Identity theft protection can monitor credit activity and alert you when certain personal information appears in places where it could signal trouble. These services cannot prevent every form of identity theft. However, alerts can help you spot suspicious activity earlier. If you discover that someone has actually used your identity, document what happened and begin the recovery process quickly. See my tips and best picks on Best Identity Theft Protection at CyberGuy.com.
公用事业账户可能比你想象的更能暴露你的个人信息。你的地址、账单详情和账户信息能给骗子提供足够的个人背景,让虚假来电、短信或邮件听起来真实可信。我们仍不清楚此次泄露的全貌。这种不确定性更是保持警惕、而非等到所有答案揭晓才采取预防措施的理由。留意你的账户,如果敏感信息泄露请考虑冻结信用,并对紧急的公用事业信息保持怀疑态度。我们往往别无选择,只能接受特定的电力或燃气供应商,这使得保护客户被迫交出的信息显得尤为重要。
A utility account can reveal more about you than you might expect. Your address, billing details and account information can give scammers enough personal context to make a fake call, text or email sound legitimate. We still do not know the full scope of this breach. That uncertainty is another reason to stay alert rather than wait for every answer before taking precautions. Watch your accounts, consider freezing your credit if sensitive information was exposed and be skeptical of urgent utility messages. We often have little choice about who provides our power or gas, which makes protecting the information customers hand over especially important.
如果一家公司提供你现实生活中无法离开的基本服务,它是否应该面临更严格的要求来保护你别无选择只能提供的个人信息?请通过 CyberGuy.com 联系我们,告诉我们你的看法。注册我的免费 CyberGuy 报告
If a company provides an essential service you cannot realistically live without, should it face tougher requirements for protecting the personal information you have no choice but to give it? Let us know by writing to us at CyberGuy.com. Sign up for my FREE CyberGuy Report