CenterPoint Energy confirms customer personal data taken from an external system

F
firmly

Utility customers must share personal details to get electricity and gas. Houston-based CenterPoint Energy told the SEC it learned of an online post claiming a customer dataset, then confirmed an unauthorized third party obtained personal information relating to a portion of customers through one of its external-facing systems. Electric and gas delivery was not impacted. The company says the incident is not reasonably likely to be material to its financials.



In a Form 8-K covered by Reuters around September 14–15, 2026, CenterPoint said it activated incident response, hired third-party experts, and notified law enforcement and certain regulators. SecurityWeek (September 15, 2026) reported the utility serves roughly 7 million metered customers across Indiana, Minnesota, Ohio, and Texas. WBIW in Indiana (September 21, 2026) covered possible exposure for Indiana customers. The investigation is ongoing, and the company says it will notify affected customers when the scope is known.

A threat actor publicly claimed about 7.49 million records and listed alleged fields such as names, phones, service and billing addresses, account numbers, billed amounts, and partial Social Security numbers, with access claimed from August 17 to September 1 via a public API. Those figures and field lists are claims, not company-confirmed counts. Reuters and the SEC filing do not confirm the 7.49 million figure.

Serey respects user privacy and tries not to hold a warehouse of sellable identity files. That can reduce what a breach can harvest, but it is not absolute security and does not mean hacking always finds nothing.

Comments

Write your comment...