News

CenterPoint Energy Confirms Customer Data Theft After Hacker Leaked 7.49 Million Utility Records

CenterPoint Energy's 14 September 2026 Form 8-K (Item 8.01 Other Events) confirms unauthorized access to personal information for a portion of customers. A hacker claimed 7.49 million records. Electric and gas delivery was not disrupted.

CenterPoint Energy Confirms Customer Data Theft After Hacker Leaked 7.49 Million Utility Records

CenterPoint Energy, Inc. filed a Form 8-K dated 14 September 2026 after an online post claimed a customer data set. The company activated incident response, hired third-party experts, and later determined that an unauthorized third party obtained personal information relating to a portion of customers through one external-facing system. The Record and BleepingComputer reported the filing on 15 September.

The disclosure is Item 8.01 Other Events. It is not an Item 1.05 Material Cybersecurity Incident filing.

Electric and gas delivery was not impacted and remains operational. The company does not believe a material financial impact is reasonably likely. It reported the matter to law enforcement, said it will notify affected customers as required, and expects cyber insurance to offset costs. CenterPoint serves about 7 million metered customers across Indiana, Minnesota, Ohio, and Texas.

A hacker using the alias 4d722e4d656f77 told BleepingComputer they took 7.49 million records, including names, phones, addresses, account numbers, billing amounts, and partial Social Security numbers, by iterating a public API that lacked rate limits and a web application firewall. A company spokesperson declined to confirm that count. The 8-K confirms only a portion of customers and does not publish a number.

SecurityWeek said about 2.5 GB was posted on a cybercrime forum on 12 September, and that the hacker threatened future infrastructure attacks. SecurityWeek also said it cannot confirm the dump is complete or genuine. Proposed class actions, as reported by BleepingComputer, allege a breach window from about 17 August to 1 September.

Related theft and lure tape includes how to prevent phishing attacks, the Revolut fake government-request breach, and HBO Max Reddit ClickFix malware.

CenterPoint customers should watch for official breach notices and freeze credit, then watch for utility-themed phishing. Security teams at other utilities should audit external APIs for auth, rate limits, and WAF coverage now.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free