CenterPoint Energy confirmed a breach after a hacker published what they claim are 7.5 million customer records. Confirmation followed the dump. If your cybersecurity program still treats a sampled audit as proof that threat-protection is alive, you are watching the same sequence from the cheap seats.

Texas customers lost billing identity, service locations, and whatever else sat in the same extract. Once a utility dump is public, incident response is theater you perform for people who already have the files. The attacker set the timeline. You inherited it.

CenterPoint Energy facility after the company confirmed a customer-data breach
CenterPoint confirmed the incident after a hacker leaked a stash they say holds 7.5 million customer records.

You already know the feeling. The firewall report looks calm. Brute-force alarms fired on some forgotten VPN last month and someone ticketed them. The quarterly assessment called access reviews substantially complete. The question that mattered on leak day is narrower. Could anyone prove, that morning, that bulk customer export still required a living control?

Late Proof Is How Customer Files Leave Quietly

Hack-and-leak puts your cyber security program on a clock you do not own. CenterPoint’s confirmation is useful and late. The records moved first. Legal, comms, and the SOC arrived second. That lag is where copycat claims and regulator letters get their leverage.

Defense in depth is supposed to catch an extract in motion. In practice, a lot of that depth sits at the edge: packet filters, MFA banners, EDR on laptops. The system that can pull 7.5 million rows sits behind all of that, often with a service account that has not been reviewed since the last ERP cutover. Threat detection that only watches inbound exploits will miss a quiet copy over an allowed path.

Any shop that bills, meters, ships, or insures has a file that looks like this. The blast radius is the customer table plus every replica you made for reporting. Those replicas are where a “read only” account becomes a full export. Nightly dumps to a vendor SFTP share. A BI warehouse that still trusts last year’s subnet. A cloud snapshot that nobody listed in the system of record.

SecurityWeek’s control-monitoring argument lands here for a reason. A point-in-time sample can be accurate and still miss the job that ran in August. You sampled twenty access reviews in March. The export never appeared in the sample. The control you show an auditor is a policy. The control the attacker met is a database role that still worked.

Point-in-time audits and sampled assessments offer only snapshots. Continuous monitoring is how you show a control still worked this morning, on this host, against this export path.

Operators learn this the expensive way because customer platforms get treated as back office. They are production. They hold the only copy of identity the public will recognize. If your evidence of a working deny is a slide from last quarter, the dump site is already the better logger.

672 CVEs Will Not Become Cybersecurity Evidence

Oracle’s September 2026 Critical Security Patch Update is the other pile on your desk this week. Tenable counts 672 unique CVEs across 673 updates, with 104 rated critical. Oracle E-Business Suite took 159 patches. Fusion Middleware took 153, including 78 issues reachable over the network without authentication. Oracle Utilities Applications picked up two patches, one of them remotely exploitable without a login.

Chart of Oracle's September 2026 Critical Security Patch Update covering 672 CVEs
Oracle’s September 2026 CSPU shipped 673 updates. A closed CVE is still not proof that last night’s customer extract required a living control.

If you run those stacks, you patch. You do it with a queue, a change window, and a regression test someone will try to skip. Security hardening starts with the install. Evidence is the follow-up test: the old call dies, the deny lands in the log your incident response runbook actually reads, and the reporting replica still refuses a desktop VPN session.

Monthly CSPUs, which Oracle started in May 2026, will keep arriving between the big quarterly dumps. High-severity items are 503 of this month’s 673 updates. Critical is 104. The matrix is a work queue. The failure mode is treating the bulletin as a control attestation. Two weeks in CAB with no artifact showing that customer-data threat detection fired on a real bulk read in the last 30 days leaves you in snapshot land with a larger ticket pile.

Patch the internet-facing bits first. Unauthenticated remote bugs in middleware. Anything on a shared VIP. Anything that shares a trust domain with billing. Then keep the test artifact with the change record. A screenshot from last quarter puts you back where CenterPoint’s customers already are: hoping the next extract needs a control you last proved on paper.

If You Cannot Show It Working Today, Cut the Path

You need evidence you can pull on a Tuesday. Immediate work is ugly and finite. Ongoing work is a habit. Both beat another green dashboard.

Start with the systems that can emit a customer file. Name the owners, the replicas, and the accounts that can read them. If that inventory takes more than a day, you already found the incident.

  • Today: ticket every bulk-export path you can name, including reporting databases, vendor SFTP drops, and “temporary” data lakes. Disable the unused ones before lunch. Rotate the service accounts that can still SELECT the customer table. Snapshot IAM and database audit logs before anyone “cleans up.”
  • Today: restore identity and billing from backups you actually restore. Walk the incident response steps for records already posted, including customer-notice drafts and regulator contacts you can reach after hours.
  • Every week: keep a pass/fail that authorization still denies bad reads and that volume anomalies still alert. Store the result. A pass is export telemetry that fired, plus a deny you can show, on a date a lawyer could read.
  • Every patch window: re-test reachability after ERP and middleware updates so security hardening does not rot between CSPUs. Customer-data hosts should refuse general VPN pools. Break-glass should live on a separate control plane.

Keep the firewall. Keep the brute-force lockouts. Treat them as table stakes. The control that would have caught a 7.5 million-row extract lives on the data path, in authorization, in volume alerts, and in a restore you have actually done.

The next leak will not wait for your quarterly sample. Pull the proof now, while the records in the news still belong to someone else.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.