CenterPoint Energy, the Houston-based utility that supplies electricity and natural gas to roughly 7 million metered customers across Texas, Indiana, Minnesota and Ohio, has confirmed that an unauthorized third party obtained personal information belonging to some of its customers through an external-facing system. The company disclosed the incident in a Form 8-K filing with the U.S. Securities and Exchange Commission on September 14, 2026. Security Affairs reported on September 16, 2026 that CenterPoint admitted an intruder stole personal information belonging to some of its customers after a hacker began advertising the data online.
The disclosure arrived after a threat actor using the alias 4d722e4d656f77 posted on a popular cybercrime forum on September 12, 2026, claiming to have exfiltrated 7.49 million customer records. BleepingComputer reported on September 15, 2026 that the investigation started after the company discovered the online post from the threat actor. The intruder told the outlet that the data included names, phone numbers, service and billing addresses, account numbers, billing amounts and partial Social Security numbers.
According to the attacker, the records were pulled by iterating through millions of identifiers on CenterPoint's public API, which they described as lacking rate limiting, web application firewall protection, authentication tokens and other defenses against automated access. The Register reported on September 15, 2026 that the person claiming responsibility said they extracted 7.49 million of CenterPoint's files from a poorly secured API. The same report noted that the alleged data dump includes customer names and contact details, billing data, move-in dates, driver's license information and the last four digits of Social Security numbers.
CenterPoint Energy is a significant piece of American energy infrastructure. It employs roughly 8,300 people, generates over $9.3 billion in annual revenue and operates power generation facilities, according to BleepingComputer. The company said its electric and gas services were not impacted by the cyberattack, and it does not believe the incident is reasonably likely to materially affect its business or financial condition.
Key Facts
In its September 14, 2026 Form 8-K, CenterPoint Energy stated that while the investigation remains ongoing, the company has determined that an unauthorized third party obtained personal information relating to a portion of its customers through one of its external-facing systems. The filing does not name the threat actor, does not confirm the 7.49 million figure and does not specify which data fields were exposed. The company said it is continuing to work with third-party experts to determine the scope of customers and personal information affected and intends to notify affected customers and regulatory authorities as required by applicable law.
The company said its electric and gas services were not impacted by the cyberattack, and it does not believe the incident is reasonably likely to materially affect its financial condition or results of operations. CenterPoint has activated its incident-response procedures, hired third-party cybersecurity experts, strengthened protections on its systems, and reported the incident to law enforcement and regulators. The Register reported on September 15, 2026 that when asked for comment on the veracity of the claims, CenterPoint said its filing speaks for itself.
The threat actor offered a 2.5 GB archive for download, according to Security Affairs, which reported on September 16, 2026 that the hacker claimed to have obtained well over 7.49 million records in seven .jsonl files, plus a CSV version. The attacker also claimed that the company attempted to stop the data dump midway, and that without that intervention the total could have reached 17.44 million records. The hacker mocked the company as a $26.2 billion operation with weak protection and warned that next time they would not simply pull data but would start attacking the main infrastructure.
SecurityWeek reported on September 15, 2026 that the claims were made on a popular cybercrime forum on September 12. The outlet noted that the threat actor allegedly obtained nearly 7.5 million user records and made available a 2.5 GB archive file. SecurityWeek also observed that it cannot confirm the validity of the data and that it is not uncommon for hackers to make false or exaggerated claims. The report added that this is not the first time a hacker has claimed to have stolen CenterPoint Energy data. In 2024, the company was one of several energy companies targeted by an access broker named AntiBrok3rs. A few months later, a different hacker claimed to have obtained the company's data. In both cases, the stolen data was believed to have come from the Cl0p ransomware group's 2023 MOVEit campaign, with analysts believing the CenterPoint Energy data originated from a third party rather than directly from the company's systems.
Analysis
The most striking detail in this case is not the size of the claimed haul but the alleged method. According to the threat actor, the data was exposed through an API that lacked rate limiting, WAF protection, authentication and token validation. If accurate, that would mean a public-facing interface allowed automated enumeration of millions of identifiers with no meaningful friction. SecurityWeek reported on September 15, 2026 that the hacker claimed to have obtained nearly 7.5 million user records, and the outlet cautioned that the validity of the data has not been confirmed. Even so, the technical description aligns with a class of vulnerability that security researchers have warned about for years: APIs are frequently deployed as thin wrappers around databases without the same defensive layers applied to web applications.
What this really means is that the perimeter many utilities rely on is not a wall but a collection of endpoints, and each endpoint carries its own configuration risk. An API that returns billing details, service addresses and partial Social Security numbers is not a minor exposure. It is a direct pipeline into identity theft, phishing and account takeover. The attacker's claim that a simple CAPTCHA key could have stopped the dump, and that its absence allowed the theft to continue, underscores how small the gap may have been between a contained incident and a catastrophic one.
The company's response has been procedurally correct. CenterPoint filed a Form 8-K with the SEC on September 14, 2026, activated incident-response procedures, engaged third-party experts, strengthened protections and notified law enforcement and regulators. Yet the filing deliberately avoids confirming the number of affected customers, the specific data types or the identity of the threat actor. That restraint is legally understandable, but it leaves customers and regulators with an incomplete picture. Multiple lawsuits proposing class actions have already been filed in federal courts by law firms representing potentially impacted customers, alleging the data breach occurred between August 17 and September 1. The legal exposure may prove more consequential than the technical one.
The bigger picture here is that critical infrastructure operators are being tested not by sophisticated nation-state campaigns alone but by opportunists who find unguarded APIs and automate their exploitation. CenterPoint serves roughly 7 million metered customers and employs about 8,300 people, with over $9.3 billion in annual revenue. The claimed 7.49 million records, if verified, would represent a dataset larger than the company's own customer base, a discrepancy that could indicate duplication, historical records or exaggeration. Independent outlets, including The Register and SecurityWeek, have not been able to fully validate the leaked dataset. That uncertainty does not diminish the operational lesson. It sharpens it.
Why It Matters
Utilities are not ordinary businesses. They hold sensitive customer data and they operate systems that millions of people depend on for heat, light and safety. CenterPoint has said its electric and gas services were not impacted, and that is the most important operational fact in the disclosure. But the theft of names, addresses, account numbers, billing amounts and partial Social Security numbers creates a durable risk for customers that persists long after the intrusion is contained. Unlike a password, a Social Security number cannot be easily changed.
The incident also arrives at a moment of heightened concern about attacks on critical infrastructure. The Register reported on September 15, 2026 that disruptive attacks have recently been recorded at facilities in Poland and the UK, and that more than 100 US water systems were affected by attacks in July. SecurityWeek noted a 240,000-record data breach at Japan's Digital Agency and the Revolut data breach as related incidents. The pattern is clear: attackers are probing the less glamorous, less defended layers of essential services. A utility API may not control a turbine, but it can expose the customers who rely on one.
For CenterPoint, the immediate priorities are containment, notification and transparency. The company has said it will notify affected customers and regulatory authorities as required by applicable law. The scope of that notification will depend on an investigation that is still ongoing. What regulators and customers will want to know is simple: how many people were affected, what exactly was taken, and what has been changed to prevent a repeat. Those answers will shape both the legal aftermath and the public trust that utilities cannot easily rebuild once it is lost.
Next Up
CenterPoint Energy is expected to continue its investigation with third-party cybersecurity experts and to provide further updates as the scope of affected customers and personal information becomes clearer. The company has said it intends to notify affected customers and regulatory authorities as required by applicable law, and it has already reported the matter to law enforcement. The class action lawsuits filed in federal courts will proceed, and they will likely seek discovery on the company's API security posture, including the presence or absence of rate limiting, WAF protection and authentication controls.
Watch for several developments. First, whether CenterPoint amends its SEC disclosures to confirm a specific number of affected individuals. Second, whether the 2.5 GB archive and its 7.49 million records are independently verified or debunked. Third, whether regulators open a formal inquiry into the utility's data protection practices. Fourth, whether the incident prompts broader scrutiny of API security across the energy sector, where operational technology and information technology increasingly intersect. The answers will determine whether this remains a data breach story or becomes a turning point for how utilities defend their digital front doors.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.