Report
CenterPoint Energy says hackers took customer data from an external-facing system
CenterPoint Energy has told regulators that hackers obtained personal information belonging to some of its customers, after a dark web post claimed to offer stolen data. The source does not describe any protective step for customers beyond the company's own notification process, so that part of the picture remains thin.
CenterPoint Energy, a Houston-based electric and gas utility, filed an 8-K form with the Securities and Exchange Commission confirming it became aware this month of a dark web post claiming to offer data stolen from the company. An investigation into those claims found that hackers did obtain personal information relating to a portion of the company's customers through one of its external-facing systems.
The company said delivery of electric and gas services has not been impacted. It also said it is continuing to work with third-party experts to determine the scope of customers and personal information affected, and intends to notify affected customers and regulatory authorities as required by applicable law. CenterPoint said it reported the incident to law enforcement in addition to the regulatory filing.
The cybercriminal post itself claims roughly 7.5 million records were taken, including customer names, account information, the last four digits of Social Security numbers and billing information. A CenterPoint spokesperson declined to answer other questions about that post. The company's filing does not confirm those figures, and the source does not treat them as established. CenterPoint said it will incur some costs related to the investigation but that the incident is not likely to have a material impact on its finances.
For readers trying to judge their own exposure, the useful detail is the entry point: the company attributes the access to an external-facing system rather than to its service delivery. CenterPoint provides power and natural gas to 7 million customers across Indiana, Minnesota, Ohio and Texas, so the pool of potentially affected people is large even if the confirmed scope is described only as a portion of customers. The source does not say which customers, how they will be told, or what they should do in the meantime. That gap matters: the protective step a reader can act on is not yet specified in the evidence available.
This is also not the company's first such disclosure. Last year CenterPoint announced it was investigating another data breach tied to a 2023 incident in which hackers stole customer information through a popular file sharing platform. The source does not connect the two incidents, and no such link should be assumed.
Our reading
Our reading is that the confirmed exposure point is an external-facing system, which is the detail small teams can act on, while the source leaves the customer-facing protective step and the true scope of affected records unresolved.
Source details and supporting facts
Each line is stated by the page named above it.
Stated by The Record
- CenterPoint Energy filed an 8-K form with the Securities Exchange Commission confirming it became aware of a dark web post this month claiming to offer data stolen from the company.
- An investigation revealed hackers obtained personal information relating to a portion of the company's customers through one of its external-facing systems.
- CenterPoint Energy said the delivery of electric and gas services has not been impacted by the incident.
- The cybercriminal post claims about 7.5 million records were stolen and contained customer names, account information, the last four digits of Social Security numbers, billing information and more.
- A spokesperson for CenterPoint Energy declined to answer other questions about the cybercriminal post.
- CenterPoint Energy provides power and natural gas to 7 million customers across Indiana, Minnesota, Ohio and Texas.
- Last year the company announced it was investigating another data breach related to a 2023 incident where hackers stole customer information through a popular file sharing platform.
Sources
- The RecordText stored 15 September 2026
How this story was checked. Written from the 1 page listed above, stored 15 September 2026; claims checked against that stored text on 15 September 2026.
What that means
- 7 of 7 reported statements were confirmed against the page that carries them; the rest were removed rather than published.
- Figures in the text were required to appear in the stored source text: yes. Identifiers: yes.
- The check reads stored text only: no claim rests on a fresh look that did not happen.
- Where the reporting was silent, the text says so instead of filling the gap.
More from Security
Report
Spain's AEPD logs its first report of an AI-agent data breach — unverified, but with a concrete credential warning
Brief
Google releases September 2026 patches for Pixel, fixing actively exploited zero-day
Brief