CenterPoint Energy Confirms Data Breach Exposing Customers’ Personal Information
CenterPoint Energy confirmed an unauthorized third party accessed customer personal data via an external system, disclosed in an SEC Form 8-K filing.
CenterPoint Energy disclosed in a September 14, 2026 Form 8-K that an unauthorized third party obtained personal information of some customers through one of the company's external systems. The company learned of the incident after an online post claimed possession of a customer dataset, then activated incident-response protocols and engaged external forensic specialists. Electric and gas delivery operations were unaffected and the company does not expect a material financial impact, though response, notification, and compliance costs are being incurred. The number of affected customers, data types, and threat actor remain undisclosed as the investigation continues.
- Unauthorized third party accessed customer data via an external system
- Breach discovered after an online post claimed possession of a customer dataset
- No disruption to electric and gas delivery operations
- Scope, data types, and threat actor remain under investigation
- Law enforcement and certain regulators already notified
Full article552 words · extracted from gbhackers.com · click to collapse
CenterPoint Energy has confirmed that an unauthorized third party accessed personal information belonging to some of its customers by compromising one of the utility provider’s external systems.
The Houston-based energy company disclosed the incident in a Form 8-K filing with the U.S. Securities and Exchange Commission dated September 14, 2026. CenterPoint learned of the potential breach after discovering an online post from a third party claiming to have a dataset containing customer information.
CenterPoint Energy Data Breach
Upon learning of the claim, the company activated its cybersecurity incident-response protocols, launched an investigation, and engaged external cybersecurity specialists to assist with forensic analysis and containment efforts.
“An unauthorized third party obtained personal information related to a portion of the Company’s customers through one of the Company’s external systems,” CenterPoint stated in the filing.
The company did not specify the type of personal information accessed, the number of potentially affected customers, the identity of the threat actor, or the specific system involved. The investigation is ongoing as CenterPoint works with third-party experts to determine the full scope of the exposure.
CenterPoint reported that the security incident has not disrupted its electric and gas delivery operations. The company said services remain operational, indicating the intrusion has not affected systems used to deliver electricity or natural gas to customers.
The utility also indicated that it does not currently believe the incident is likely to have a material impact on its financial condition or operating results.
However, the filing acknowledged that CenterPoint has already incurred response-related expenses and expects additional costs as its investigation, remediation, notification, and compliance efforts continue.
These expenses may include digital forensics work, system hardening, legal and regulatory support, customer notifications, identity protection services, and potential incident recovery measures.
CenterPoint said it maintains customary cybersecurity insurance and expects its coverage to help offset breach-related costs. The ultimate financial impact will depend on the scope of affected records, regulatory obligations, litigation exposure, and available insurance proceeds.
CenterPoint intends to notify affected customers and regulatory authorities as required by law once it determines which individuals and data elements were involved. The company has already reported the incident to law enforcement and notified certain regulatory authorities.
The filing cautioned that the scope of the incident could be broader than currently understood, a common risk when investigating breaches of externally accessible systems.
Internet-facing infrastructure remains a target for attackers, as it can provide an initial foothold into corporate environments. Security teams typically investigate whether exposed systems have suffered from credential compromise, unpatched vulnerabilities, insecure remote access, web application flaws, or weaknesses in identity and access controls.
For customers, the disclosure highlights the importance of remaining vigilant for phishing messages, fraudulent account activity, and social engineering attempts that may use personal details obtained during a breach.
Customers should independently verify unexpected communications claiming to be from CenterPoint and avoid sharing account credentials or financial information through unsolicited links, emails, or phone calls.
CenterPoint has not yet provided a timeline for completing its investigation or for beginning direct notifications to affected individuals.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/centerpoint-energy-confirms-data-breach/