Developing: CenterPoint Confirms the Breach It Was Investigating
This is an update to our earlier coverage of the incident CenterPoint Energy first disclosed in a Form 8-K after a threat actor's September 1 forum post claiming a stolen customer database. In the day since that filing, the story has moved from "investigating a claim" to a confirmed data-theft incident, and the attacker has escalated by publishing the alleged data and issuing a direct threat against the utility's physical infrastructure.
CenterPoint Energy now says, in a statement reported by both SecurityWeek and BleepingComputer, that "an unauthorized third party obtained personal information relating to a portion of the Company's customers" through one of its external-facing systems. That is a firmer statement than the SEC filing's language of a claim under investigation — CenterPoint is no longer describing this as an unverified forum post, but as a confirmed theft of customer data.
What's New Since Yesterday
| Field | Details |
|---|---|
| Status change | CenterPoint moved from "investigating a forum claim" to confirming data theft occurred |
| Data publication | Threat actor posted a 2.5GB archive of the alleged dataset to a cybercrime forum on September 12, 2026 |
| Alleged breach window | August 17 – September 1, 2026 |
| Attack vector detail | Public API iterated through millions of customer IDs; API reportedly lacked rate limiting, a WAF, and other automated-access safeguards |
| New threat | Attacker threatened to move from data theft to attacking "main infrastructure" if ignored |
| Extortion angle | Attacker claims CenterPoint did not respond to its communications before the leak was published |
The Leak Goes Public
Where yesterday's disclosure centered on a forum post claiming to sell a database, the attacker has since made a 2.5GB archive of the alleged data directly available for download on the same cybercrime forum, dated September 12, 2026. SecurityWeek and BleepingComputer both note the figure of roughly 7.49 million customer records first reported still applies to this published set, though — as with the original claim — the authenticity and completeness of the dump has not been independently verified, and CenterPoint has not confirmed the exact record count.
The attacker also claims the breach activity spanned August 17 to September 1, 2026, giving the incident a roughly two-week window rather than a single point-in-time compromise — consistent with the API-scraping method described below.
A More Specific Attack Vector
BleepingComputer's reporting adds detail beyond yesterday's account of an unspecified "company-managed API." The outlet reports the threat actor exploited a public-facing CenterPoint API by iterating through millions of sequential or enumerable customer/account IDs, and that the API lacked rate limiting, a Web Application Firewall, and other controls that would normally catch or slow this kind of automated, large-scale scraping. If accurate, this points to an authorization/design gap — an endpoint that returned customer records to anyone who could guess or enumerate a valid ID — rather than a traditional network intrusion or credential compromise.
Escalation: A Direct Threat to the Grid
The most significant new development is the attacker's own words. In the forum post accompanying the leaked archive, the threat actor wrote that "next time we won't simply pull data, we'll start attacking the main infrastructure" — an explicit threat to move from data theft toward operational technology or grid-facing systems if the utility does not engage. CenterPoint has not publicly responded to this specific threat, and there is no indication from either outlet that electric or gas delivery systems were targeted or are at elevated technical risk as a result of this data-theft incident. Security researchers routinely caution that such threats from data-leak actors are frequently used as extortion leverage and are not evidence of actual OT/ICS access — but the statement is notable given CenterPoint's role delivering power and gas to roughly seven million customers across Texas, Indiana, Minnesota, and Ohio.
Not CenterPoint's First Brush With a Data Broker
SecurityWeek's report notes this is not the first time CenterPoint's name has surfaced in connection with stolen data claims: in 2024, the company was among several energy-sector organizations named by an access broker operating under the alias "AntiBrok3rs." That episode is separate from both this incident and the 2023 file-sharing-platform exposure referenced in CenterPoint's current SEC disclosure — three distinct incidents across three years underscore how frequently utilities are targeted by data-focused threat actors, even when operational systems remain untouched.
Where Things Stand
- CenterPoint has confirmed data theft occurred but still has not confirmed the 7.49 million-record figure or validated the published archive
- The company says it has notified law enforcement and regulators and continues to work with third-party cybersecurity experts
- No customer notification timeline, affected-state breakdown, or credit-monitoring offer has been announced as of publication
- The infrastructure-attack threat is unconfirmed and unverified — treat it as an extortion statement, not a confirmed operational-technology risk, pending any further disclosure
The guidance for affected customers from yesterday's article — watch for an official notification letter, be skeptical of unsolicited "confirm your account" contact, monitor billing statements, and consider a credit freeze given the claimed partial-SSN exposure — remains unchanged and still applies.