CenterPoint Energy Confirms Customer Data Breach After Hack

Texas-based utility CenterPoint Energy has confirmed that an unauthorized intruder accessed customer information after data allegedly stolen from its systems surfaced on a cybercrime forum.[1][5][11][15] The company disclosed the incident in a recent filing with the U.S. Securities and Exchange Commission, stating that personal information tied to a portion of its customer base was obtained through one of its external-facing systems.[1][5][15] CenterPoint emphasized that the breach has not disrupted the delivery of electric or gas services and that it does not currently expect the incident to have a material impact on its financial performance.[1][5][15]

The confirmation follows claims by a threat actor that they had extracted and leaked a large customer dataset associated with CenterPoint, describing a trove of roughly 7.49 million records hosted in a multi-gigabyte archive on an underground forum.[1][8][9][12][14] Dark web monitoring summaries and legal-investigation sites report that the data, presented in raw JSON and filtered CSV formats, allegedly includes names, phone numbers, service and billing addresses, account identifiers, premise IDs, billing amounts, payment status, service details, autopay and paperless billing flags, and partial Social Security numbers.[8][9][14] Both independent analysts and news outlets note that the authenticity and completeness of the leaked dataset have not yet been verified, and the number of affected individuals could differ from the claimed record count.[1][8][9][12][14]

In its SEC filing, CenterPoint said it activated incident response procedures and engaged third-party cybersecurity experts after learning of an online post claiming access to customer information.[5][15] The company’s investigation concluded that an unauthorized third party had obtained personal data from one of its Internet-exposed systems, but it has not publicly identified a specific vulnerability or software flaw tied to the intrusion.[1][5][15] Insurance-focused reporting on the filing adds that CenterPoint expects to incur costs related to the investigation, remediation, and customer communication, though it anticipates that its cybersecurity insurance coverage will offset some of those expenses.[15] Separate civil complaints filed by customers allege that attackers may have exploited weaknesses in CenterPoint’s online account infrastructure, particularly a guest bill-pay feature, but those lawsuits also note that the utility has not yet verified the full scope of the alleged breach.[4]

Early legal filings describe the incident as potentially affecting millions of customers across multiple states, with estimates in the complaints ranging between roughly 6.7 million and 7 million impacted individuals depending on the case.[4] Plaintiffs claim that exposed data includes names, phone numbers, addresses, billing information, and Social Security numbers, arguing that such details materially raise the risk of identity theft and fraud.[4][9] At the time of writing, observers tracking breach notifications report that formal disclosures to state attorneys general and federal regulators specific to this 2026 incident have not yet appeared in public dockets, suggesting that regulatory review and notification processes may still be unfolding.[9]

The latest breach comes on the heels of earlier exposure of CenterPoint-related customer information in the wider MOVEit Transfer supply-chain attacks, where the Cl0p ransomware group exploited a critical Progress Software flaw tracked as CVE-2023-34362 on systems operated by energy-efficiency contractor CLEAResult.[3] That prior incident, which affected millions of records linked to CenterPoint rebate and demand-response programs, similarly underscored the sensitivity of utility customer datasets and the cascading risk posed by third-party vendors.[3] While the new breach appears to involve CenterPoint’s own external-facing environment rather than a contractor’s infrastructure, the repeated compromise of customer information is likely to invite closer regulatory and industry scrutiny of how utilities manage and segment externally accessible systems.[1][3][5]

Security analysts warn that detailed customer and billing records tied to a critical infrastructure provider can be weaponized for targeted phishing, account takeover, and reconnaissance against operational and customer-service systems.[9][14] Threat intelligence briefings on the CenterPoint leak highlight the risk that attackers could use exposed data to impersonate customers, redirect payments, or socially engineer support staff, even if core grid and gas-distribution networks remain segmented.[14] Customers are being urged by attorneys and consumer advocates to monitor account statements and credit reports, enable multi-factor authentication where available, and treat unsolicited communications referencing their utility accounts with heightened suspicion.[4][8][9] As CenterPoint’s investigation continues and regulators evaluate the incident, utilities across the sector are expected to reassess guest-access features, external-facing portals, and data-minimization practices to reduce the blast radius of future compromises.[4][14][15]

References

  1. Texas Utility CenterPoint Energy Confirms Breach After …
  2. centerpointenergy.com | Search the Data Breach
  3. CenterPoint energy hit with multiple proposed class actions …
  4. CenterPoint Energy discloses customer data breach in …
  5. CenterPoint Energy Data Breach Investigation
  6. CenterPoint Energy Data Breach Exposes 7.49M Records
  7. CenterPoint Energy confirms intruder helped themselves to customer information
  8. Post
  9. CenterPoint Energy data leak of 7.49 million customers – Pulse
  10. Texas Utility Discloses Customer Data Breach in SEC Filing

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply