Back Cyberinsider CenterPoint Energy confirms data breach after hacker claims 7.49M records
CenterPoint Energy has confirmed that an unauthorized third party obtained personal information belonging to some of its customers through an external-facing system.
The disclosure follows an online post in which a threat actor claimed to have stolen and released information on approximately 7.49 million customers. However, CenterPoint has not confirmed that figure or the authenticity of the published dataset.
In a Form 8-K filed with the US Securities and Exchange Commission on September 14, 2026, CenterPoint said it became aware in September of a third-party post claiming to possess customer information. The utility activated its cybersecurity incident response procedures, brought in external cybersecurity specialists, and implemented additional measures to protect its systems.
The investigation subsequently determined that an unauthorized party had obtained personal information associated with “a portion” of CenterPoint customers through one of the company's externally accessible systems. CenterPoint has not disclosed how the system was compromised, how long it was exposed, or precisely what information was accessed.
CenterPoint Energy is a Houston-based electric and natural gas utility whose operations include CenterPoint Energy Houston Electric and CenterPoint Energy Resources. Its shares trade on the New York Stock Exchange under the ticker CNP. The company said the incident did not affect electricity and gas delivery, which remained operational.
The SEC filing appears to correspond with a forum post attributed to a threat actor using the alias “4d722e4d656f77.” The poster claimed to have obtained more than 7.49 million CenterPoint records from an API controlled by the company and alleged that the endpoint lacked adequate authentication, rate limiting, and other protections.
The post says the stolen data included fields such as customer names, phone numbers, email addresses, service and billing addresses, account and premise identifiers, billing amounts, payment information, autopay and paperless billing status, and the last four digits of Social Security numbers. The actor also claimed that substantially more data could have been extracted before CenterPoint intervened.
Those technical details and the claimed record count remain allegations by the threat actor and were not verified in CenterPoint's 8-K. The company has only confirmed unauthorized access to personal information through an external-facing system and said its investigation is still determining which customers and data types were affected.
CenterPoint has notified law enforcement and certain regulators and says it will notify affected customers and additional authorities where required. It expects to incur incident-response expenses but believes its cybersecurity insurance will offset some of those costs. The company currently does not expect the breach to materially affect its financial condition or operating results.
Customers should treat unexpected calls, emails, or text messages claiming to be from CenterPoint with caution, particularly when they reference account balances or service information. Affected individuals should monitor financial accounts and credit reports, consider placing a credit freeze, and independently CenterPoint through official channels rather than using links or phone numbers supplied in unsolicited messages.
HBO Max account hijacked in PasteSwitch malware campaign
Logitech Options+ flaw lets attackers gain Windows SYSTEM privileges
Nintendo warns of Switch code execution flaw via on-screen QR codes
Malicious Twitch extension exposed OAuth tokens of 30,000 users
Revolut handed customer data to fraudsters using a government email domain
Telegram Desktop bug lets poisoned messages steal exported chat histories
Alex Lekander is the Editor-in-Chief and owner of CyberInsider.com. With a passion for cybersecurity and privacy topics, Alex launched this website in 2020. His background and expertise cover privacy research, technical writing, software testing, and site administration. He holds a Bachelor of Science and a Master of Science from Johns Hopkins University.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
