Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2868+ Articles
168+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. CenterPoint Energy Confirms Data Theft as Hacker Leaks Files, Threatens Grid Attack
CenterPoint Energy Confirms Data Theft as Hacker Leaks Files, Threatens Grid Attack
NEWS

CenterPoint Energy Confirms Data Theft as Hacker Leaks Files, Threatens Grid Attack

CenterPoint moves from 'investigating' to confirmed data theft as the alleged attacker publishes a 2.5GB archive and threatens infrastructure attacks.

Dylan H.

Security Engineer

September 16, 2026
5 min read

Developing: CenterPoint Confirms the Breach It Was Investigating

This is an update to our earlier coverage of the incident CenterPoint Energy first disclosed in a Form 8-K after a threat actor's September 1 forum post claiming a stolen customer database. In the day since that filing, the story has moved from "investigating a claim" to a confirmed data-theft incident, and the attacker has escalated by publishing the alleged data and issuing a direct threat against the utility's physical infrastructure.

CenterPoint Energy now says, in a statement reported by both SecurityWeek and BleepingComputer, that "an unauthorized third party obtained personal information relating to a portion of the Company's customers" through one of its external-facing systems. That is a firmer statement than the SEC filing's language of a claim under investigation — CenterPoint is no longer describing this as an unverified forum post, but as a confirmed theft of customer data.


What's New Since Yesterday

FieldDetails
Status changeCenterPoint moved from "investigating a forum claim" to confirming data theft occurred
Data publicationThreat actor posted a 2.5GB archive of the alleged dataset to a cybercrime forum on September 12, 2026
Alleged breach windowAugust 17 – September 1, 2026
Attack vector detailPublic API iterated through millions of customer IDs; API reportedly lacked rate limiting, a WAF, and other automated-access safeguards
New threatAttacker threatened to move from data theft to attacking "main infrastructure" if ignored
Extortion angleAttacker claims CenterPoint did not respond to its communications before the leak was published

The Leak Goes Public

Where yesterday's disclosure centered on a forum post claiming to sell a database, the attacker has since made a 2.5GB archive of the alleged data directly available for download on the same cybercrime forum, dated September 12, 2026. SecurityWeek and BleepingComputer both note the figure of roughly 7.49 million customer records first reported still applies to this published set, though — as with the original claim — the authenticity and completeness of the dump has not been independently verified, and CenterPoint has not confirmed the exact record count.

The attacker also claims the breach activity spanned August 17 to September 1, 2026, giving the incident a roughly two-week window rather than a single point-in-time compromise — consistent with the API-scraping method described below.

A More Specific Attack Vector

BleepingComputer's reporting adds detail beyond yesterday's account of an unspecified "company-managed API." The outlet reports the threat actor exploited a public-facing CenterPoint API by iterating through millions of sequential or enumerable customer/account IDs, and that the API lacked rate limiting, a Web Application Firewall, and other controls that would normally catch or slow this kind of automated, large-scale scraping. If accurate, this points to an authorization/design gap — an endpoint that returned customer records to anyone who could guess or enumerate a valid ID — rather than a traditional network intrusion or credential compromise.

Escalation: A Direct Threat to the Grid

The most significant new development is the attacker's own words. In the forum post accompanying the leaked archive, the threat actor wrote that "next time we won't simply pull data, we'll start attacking the main infrastructure" — an explicit threat to move from data theft toward operational technology or grid-facing systems if the utility does not engage. CenterPoint has not publicly responded to this specific threat, and there is no indication from either outlet that electric or gas delivery systems were targeted or are at elevated technical risk as a result of this data-theft incident. Security researchers routinely caution that such threats from data-leak actors are frequently used as extortion leverage and are not evidence of actual OT/ICS access — but the statement is notable given CenterPoint's role delivering power and gas to roughly seven million customers across Texas, Indiana, Minnesota, and Ohio.

Not CenterPoint's First Brush With a Data Broker

SecurityWeek's report notes this is not the first time CenterPoint's name has surfaced in connection with stolen data claims: in 2024, the company was among several energy-sector organizations named by an access broker operating under the alias "AntiBrok3rs." That episode is separate from both this incident and the 2023 file-sharing-platform exposure referenced in CenterPoint's current SEC disclosure — three distinct incidents across three years underscore how frequently utilities are targeted by data-focused threat actors, even when operational systems remain untouched.

Where Things Stand

  • CenterPoint has confirmed data theft occurred but still has not confirmed the 7.49 million-record figure or validated the published archive
  • The company says it has notified law enforcement and regulators and continues to work with third-party cybersecurity experts
  • No customer notification timeline, affected-state breakdown, or credit-monitoring offer has been announced as of publication
  • The infrastructure-attack threat is unconfirmed and unverified — treat it as an extortion statement, not a confirmed operational-technology risk, pending any further disclosure

The guidance for affected customers from yesterday's article — watch for an official notification letter, be skeptical of unsolicited "confirm your account" contact, monitor billing statements, and consider a credit freeze given the claimed partial-SSN exposure — remains unchanged and still applies.


References

  • SecurityWeek — Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data
  • BleepingComputer — CenterPoint Energy confirms customer data stolen in cyberattack
  • CosmicBytez Labs — CenterPoint Energy Warns Customers of Data Breach After Dark Web Post
#CenterPoint Energy#Data Breach#Critical Infrastructure#Utility

Related Articles

CenterPoint Energy Warns Customers of Data Breach After Dark Web Post

CenterPoint Energy confirms unauthorized access to customer data after a threat actor's dark web post claiming 7.49M stolen records.

7 min read

Origin Energy Data Breach Exposes Millions of Australian Customers

Australia's largest energy retailer has confirmed a data breach affecting up to 2 million customers, with exposed data including full names, contact...

4 min read

Major Australian Energy Supplier Confirms Customer Data Compromised

Origin Energy confirmed that customer data was exposed in a recent breach, as the company works to assess how many Australians are affected.

3 min read
Back to all News