CenterPoint Energy Confirms Breach After Threat Actor's Dark Web Post
CenterPoint Energy, the Houston-based electric and natural gas utility that delivers power and gas to roughly seven million metered customers across Texas, Indiana, Minnesota, and Ohio, has confirmed that an unauthorized third party obtained customer personal information through one of its external-facing systems. The company disclosed the incident in a Form 8-K filed with the U.S. Securities and Exchange Commission after becoming aware of a post on a cybercrime forum claiming to offer a stolen customer database.
Electric and gas delivery service was not disrupted by the incident, and CenterPoint says it does not currently believe the breach is reasonably likely to have a material financial impact — though it expects to incur ongoing investigation and remediation costs.
Incident Overview
| Field | Details |
|---|---|
| Company | CenterPoint Energy (electric and natural gas utility) |
| Attack Vector | Unauthorized access via an external-facing system, reportedly a company-managed API |
| Disclosure Post | September 1, 2026, on a cybercrime forum |
| Regulatory Filing | Form 8-K filed with the SEC (mid-September 2026) |
| Records Claimed | Approximately 7.49 million raw records / 6.73 million filtered records (unverified by CenterPoint) |
| Service Impact | None — electric and gas delivery remained operational throughout |
| Law Enforcement | Notified; investigation ongoing with third-party cybersecurity experts |
What Happened
According to CenterPoint's SEC filing, the company became aware in September 2026 of a post by a third party claiming to possess customer information taken from CenterPoint systems. Upon discovering the post, CenterPoint activated its cybersecurity incident response protocols, engaged outside cybersecurity experts, and took steps to further secure its systems. The company's investigation has since confirmed that an unauthorized third party did obtain personal information belonging to a portion of its customers through an external-facing system — though CenterPoint has not confirmed the total number of records or individuals affected, saying that work is still underway.
Separately, a threat actor using the alias "4d722e4d656f77" claimed on September 1, 2026, to have extracted and published a database of roughly 7.49 million raw records (about 6.73 million after filtering) tied to CenterPoint customers, posting what was described as the full dataset in JSON and CSV formats for download. CenterPoint has not confirmed either the 7.49 million figure or the authenticity of the published dataset, and independent researchers have cautioned that the scale, the claimed exploitation method, and the full list of exposed fields remain unverified.
Sample Data Analysis
Dark web monitoring and threat-intelligence write-ups reviewing the alleged leak describe the following fields as present in the claimed dataset:
- Customer names, phone numbers, and email addresses
- Service and billing addresses
- Account numbers and premise IDs
- Billing amounts, payment status, and current/previous/total amounts due
- Billing and due dates, and move-in dates
- Rate/service classifications
- Autopay and paperless billing enrollment status
- Partial (last four digits) Social Security numbers
- Driver's license information (per some monitoring summaries)
Because CenterPoint has not validated the published dataset, this field list should be treated as claimed, not confirmed, pending the outcome of the company's investigation.
How the Breach Reportedly Occurred
The threat actor claims the data was obtained through a company-managed API that allegedly lacked adequate authorization checks and rate-limiting protections, and suggested that an even larger dataset than what was published may have been accessible through the same weakness. CenterPoint has not corroborated this technical account. Analysts monitoring the forum post note that API-based scraping — where an authenticated or semi-public endpoint is enumerated at scale rather than compromised through a traditional intrusion — has become an increasingly common breach pattern for utilities and other large customer-facing organizations.
CenterPoint's Response
In its SEC filing, CenterPoint described the steps it has taken so far:
"The Company is continuing to work with third-party experts to determine the scope of customers and personal information affected by the Incident and intends to notify affected customers and regulatory authorities as required by applicable law."
The company also confirmed it has reported the incident to law enforcement. As of publication, CenterPoint has not disclosed a specific customer notification timeline, a breakdown of which states' customers are affected, or whether credit monitoring or identity-protection services will be offered — details typically included in formal breach notification letters once the investigation concludes.
Legal Fallout
The breach has already triggered litigation. Multiple proposed class action lawsuits have been filed in federal court alleging that CenterPoint failed to adequately protect customer data:
- Three suits filed by a Florida law firm on behalf of individual customers
- Two additional suits filed by a Texas law firm on behalf of other customers
- Plaintiffs named across the filings reside in Indiana, Texas, and Minnesota
- No class has been certified in any of the cases as of publication
- At least one additional law firm has publicly opened an investigation into the incident on behalf of potentially affected customers
This is a separate matter from a 2023 CenterPoint data incident, in which customer information was previously accessed through a file-sharing platform.
Risk Assessment
If the Claimed Dataset Is Authentic
Customers whose data was included would face elevated risk of:
- Targeted phishing and smishing referencing real account details, billing amounts, or service addresses to appear legitimate
- Synthetic identity fraud, since partial Social Security numbers combined with names, addresses, and account data can be chained with other leaked data to reconstruct a fuller identity profile
- Utility-impersonation scams, where attackers pose as CenterPoint to demand payment or "verify" account information
- Account takeover attempts against CenterPoint online accounts that reuse exposed credentials or security-question answers
Verification Caveats
- CenterPoint has confirmed a breach occurred but has not confirmed the 7.49 million-record figure, the authenticity of the leaked dataset, or the complete field list circulating in threat-intelligence summaries
- The claimed API-based collection method has not been independently verified
- The investigation into full scope and affected individuals is still in progress
What Affected Customers Should Do
- Watch for an official notification letter from CenterPoint — do not act on unsolicited calls, texts, or emails claiming to be from CenterPoint about the breach; verify through CenterPoint's official website or published customer service number instead
- Monitor billing statements for unauthorized changes to autopay, service address, or account details
- Be skeptical of urgent "confirm your account" messages that reference real billing amounts or service details — these can be used to make phishing attempts look more convincing
- Consider a credit freeze or fraud alert with the major credit bureaus, particularly given the claimed exposure of partial Social Security numbers alongside other identifying data
- Enable multi-factor authentication on your CenterPoint online account if available, and use a unique password not reused elsewhere
- Check state attorney general breach notification pages (Texas, Indiana, Minnesota, and Ohio all maintain public breach disclosure resources) once CenterPoint files formal notifications
Why This Matters
CenterPoint Energy is critical infrastructure — it delivers electric and gas service to roughly seven million metered customers across four states. A breach at a utility carries risk beyond typical consumer data exposure: the same account and billing systems that were reportedly exposed are also the systems customers rely on for service continuity, payment, and account verification. Even though delivery of electric and gas service itself was not disrupted here, the incident is a reminder that customer-facing systems at critical-infrastructure operators are high-value targets, and that API endpoints — not just traditional network intrusions — are an increasingly common path to large-scale data exposure.