HOUSTON — CenterPoint Energy has confirmed that an unauthorized third party obtained personal information belonging to some of its customers, escalating what began as an online claim into an acknowledged cybersecurity incident at one of America’s largest electric and natural gas utilities.
But one critical question remains unanswered:
How many customers were actually affected — and exactly what information was taken?
CenterPoint disclosed the incident in a Form 8-K filed with the U.S. Securities and Exchange Commission on September 14, 2026, saying it first became aware earlier in September of an online post from a third party claiming to possess a dataset containing customer information.
The Houston-based company immediately activated its cybersecurity incident-response procedures, brought in outside cybersecurity specialists and took additional measures to protect its systems.
Its investigation has since established something more serious than an unverified online claim.
CenterPoint said an “unauthorized third party obtained personal information relating to a portion” of its customers through one of the company’s external-facing systems.
That is the part that is confirmed.
What remains unknown could determine how significant the incident ultimately becomes.
CenterPoint still hasn’t said how many customers were affected
The company has not publicly disclosed the number of compromised accounts.
It has also not identified precisely which categories of personal information were taken.
CenterPoint said outside experts are continuing to determine both the number of customers affected and the specific personal information involved. The company plans to notify affected customers and regulators as required by law.
That distinction is important because much larger figures are already circulating online.
Cybersecurity websites, attorneys and lawsuits filed against CenterPoint have cited an online actor’s claim that a database containing millions of records was exposed.
One widely circulated claim puts the dataset at approximately 7.49 million raw records, with roughly 6.73 million records after filtering. The actor allegedly described information including customer names, telephone numbers, billing and service addresses, account details and other data.
But those figures have not been confirmed by CenterPoint.
They should therefore not be reported as the established number of victims.
CenterPoint’s SEC filing uses only the considerably broader phrase “a portion” of its customers.
Why the number “7 million” can be especially misleading
CenterPoint itself serves approximately 7 million metered customers across Indiana, Minnesota, Ohio and Texas, according to its current investor materials.
That creates an obvious danger for headlines.
A reader could easily interpret an online claim involving roughly seven million records to mean virtually CenterPoint’s entire customer base was compromised.
That has not been established.
A database can contain multiple records associated with one customer, historical accounts, duplicated records or other data that make the record count substantially different from the number of unique individuals involved.
Until CenterPoint completes its investigation and provides a confirmed customer count, claims that “seven million CenterPoint customers were hacked” would go beyond the available evidence.
Lawsuits allege the weakness was in an online bill-payment feature
The story was already moving into the courts even before CenterPoint’s SEC disclosure.
Several proposed class-action lawsuits were filed in federal court in Texas during the week before the company’s September 14 filing.
Houston Chronicle reported that lawsuits filed on behalf of customers allege that cybercriminals exploited CenterPoint’s guest bill-pay system, which allows payments using an account number.
The complaints contend that entering a valid account number into the feature could retrieve other customer information and allege that this mechanism became the path through which information was harvested.
Federal court records confirm multiple cases were filed against CenterPoint between September 9 and September 11, including lawsuits brought by Christa Floyd, Joyce Curry, Nathaniel Sonia, Latoya Wyche and Laurie Eirwin.
But another distinction is essential:
The guest-payment theory comes from plaintiffs’ allegations. CenterPoint’s SEC filing does not identify the affected external-facing system.
The company has confirmed unauthorized access through one of those systems but has not publicly said that guest bill pay was responsible.
Some lawsuits claim extremely sensitive information was involved
The legal complaints and online breach reports raise the possibility that the exposed information went well beyond customer names and utility account numbers.
Houston Chronicle reported that the proposed class actions allege compromised information could include names, telephone numbers, addresses, billing information and Social Security-related data.
A law firm investigating potential claims similarly said publicly available information about the alleged leak referenced names, telephone numbers, service and billing addresses, account information, billing amounts, payment status and partial Social Security numbers.
Those claims have not yet been independently established.
CenterPoint’s official filing does not specify whether Social Security numbers, financial information, passwords or payment-card information were among the information obtained.
That question matters enormously.
A breach involving names and addresses is serious.
A breach containing Social Security numbers, authentication credentials or financial information creates a significantly greater risk of identity theft and fraud.
For now, the company says determining the information involved remains part of the investigation.
There is one piece of good news: the energy system itself stayed online
Despite the theft of customer information, CenterPoint says the cybersecurity incident did not disrupt electricity or natural gas delivery.
Its electric and gas operations remain operational, according to the filing.
That difference is particularly important when dealing with a utility.
Cyber incidents targeting an energy company can potentially fall into two very different categories.
One attacks customer or corporate information technology.
The other reaches operational technology controlling physical infrastructure — grids, pipelines, substations, generating equipment or industrial-control systems.
CenterPoint has disclosed no interruption to those physical energy-delivery operations in this incident.
That means there is currently no evidence that the unauthorized access caused power outages, interfered with natural-gas distribution or compromised the company’s operational infrastructure.
But utilities have become increasingly attractive cyber targets
The CenterPoint disclosure arrives as cybersecurity risks facing electricity and energy companies are intensifying.
Reuters reported earlier this month that energy companies are confronting increasingly sophisticated attacks as utilities connect more equipment and digital systems while attackers deploy artificial intelligence to accelerate reconnaissance, social engineering and vulnerability discovery.
The concern is particularly acute because modern utilities operate both conventional information-technology networks and operational-technology systems responsible for physical infrastructure.
A successful intrusion into customer systems may expose personal information.
A successful intrusion into operational systems can potentially threaten reliability, equipment or even public safety.
CenterPoint says its own cybersecurity program includes a dedicated Cybersecurity Operations Center, incident-response procedures, third-party assessments and annual exercises designed to test its readiness. Its sustainability reporting says the company monitors risks affecting both information technology and operational technology.
The current incident shows why those defenses are receiving more scrutiny.
CenterPoint had already warned investors about cyber risk
Cybersecurity threats were not an unforeseen problem for the company.
CenterPoint’s previous securities filings have warned that cyberattacks could require substantial spending on investigation, remediation and enhanced security.
Its disclosures also acknowledge that failures in protective measures could lead to regulatory action and damage the company’s financial condition, results and reputation.
Its privacy policy shows the breadth of information potentially handled across CenterPoint’s digital services.
Depending on how a customer interacts with the company, CenterPoint says it may collect names, telephone numbers, addresses, online-account credentials, billing information, account and meter numbers, electricity-usage information and other household or demographic data.
That does not mean all — or even most — of those categories were involved in this particular breach.
It illustrates why identifying which system was compromised is so important.
CenterPoint says the financial impact should not be material
Investors received another potentially reassuring message.
As of its September 14 filing, CenterPoint said it does not believe the incident is reasonably likely to have a material effect on its financial condition or operating results.
The company nevertheless acknowledges that costs are already accumulating.
It said it has incurred expenses connected with the investigation and response and expects additional costs as the process continues.
CenterPoint also carries cybersecurity insurance, which management believes will offset related expenses.
There is an important caveat buried in the same filing.
CenterPoint lists among its risks the possibility that the scope of the incident ultimately proves larger than initially expected, alongside uncertainty over remediation expenses, insurance proceeds and regulatory obligations.
That is why the current “no material impact” assessment should be understood as management’s judgment based on information available now — not a guarantee about the final cost.
CenterPoint has also contacted law enforcement
The company has reported the incident to law-enforcement authorities and notified certain regulators.
Additional notifications are expected once investigators determine precisely who was affected.
CenterPoint said customers whose information is covered by applicable notification laws will be contacted.
That process could eventually provide the clearest answers yet about the breach because state data-breach notification rules often require companies to specify the type of personal information exposed and the approximate number of affected residents.
For now, however, those details remain unavailable.
This is much bigger than an ordinary website problem
CenterPoint is not a small regional business.
Its operating subsidiaries provide electric transmission and distribution and natural-gas services across several states, including the massive Houston metropolitan area.
At the end of 2025, CenterPoint reported more than 4 million natural-gas customers alone, while the group says it serves roughly seven million metered customers across its overall network.
That scale makes customer-data security particularly consequential.
Utility accounts contain information that can be valuable for more than conventional identity theft.
Names paired with exact service addresses, telephone numbers, billing details and account information can potentially make phishing attempts more convincing because criminals can impersonate the utility while demonstrating knowledge of a victim’s real account.
That creates a secondary risk even for customers whose most sensitive financial information was not necessarily exposed.
And unlike a streaming subscription or online shopping account, households generally cannot simply decide they no longer need electricity or natural gas.
Utilities occupy an unusually trusted and unavoidable place in people’s lives.
The breach also comes as digital infrastructure moves higher on corporate risk agendas
Corporate boards are increasingly treating digital infrastructure as a strategic vulnerability comparable with physical supply chains.
A recent Capgemini survey cited by Reuters found that companies and public institutions are strengthening contingency planning as cyber threats, geopolitical conflict and technology dependencies expose weaknesses in critical digital infrastructure.
For energy providers, the challenge is particularly acute.
They are being asked to digitize faster, connect more infrastructure, accommodate enormous new electricity demand from data centers and simultaneously defend expanding networks from increasingly automated attacks.
CenterPoint’s incident demonstrates another side of that transformation:
Even when hackers do not turn off the lights, the information behind millions of utility accounts can itself become a valuable target.
The most important fact is what CenterPoint has not said yet
The basic sequence is now established.
A third party posted online claiming to possess CenterPoint data.
CenterPoint investigated.
The company determined that an unauthorized person really had obtained personal information through an external-facing system.
Services remained operational.
Law enforcement and regulators were notified.
Cybersecurity experts were brought in.
And CenterPoint expects insurance to cover at least part of the response costs.
But nearly every question that determines the seriousness of a consumer-data breach remains open.
How many unique customers were affected?
Which states are involved?
What personal information was exposed?
Was Social Security information actually taken?
Was the system identified in the lawsuits really the point of entry?
How long did unauthorized access continue?
And perhaps most importantly:
Can the stolen information be used to commit identity theft or financial fraud?
Until those questions are answered, the biggest number surrounding the CenterPoint breach isn’t the millions of records being claimed online.
It’s the number CenterPoint itself still hasn’t disclosed.

Leave a Reply