← Blog

CenterPoint Energy Breach: SEC Confirms Customer PII Stolen

Share on X

CenterPoint Energy confirmed in a Form 8-K dated September 14, 2026 that an unauthorized party obtained personal information relating to a portion of its customers through an external-facing system. The Houston-based electric and natural gas utility said delivery operations were not affected and that customer notifications would follow as scope is finalized. The disclosure followed an online post claiming a large customer dataset — coverage that put a ~7.49 million record figure into circulation.

To be clear: CenterPoint has confirmed a real customer-data incident. It has not attested the 7.49 million headcount or the full actor field list. Treat that census as an unverified claim sitting next to a verified breach.

Canonical record: https://breachhistory.com/centerpoint-energy/centerpoint-energy-api2026. Primary coverage: BleepingComputer, Cyberinsider, Reuters SEC filing reports.

What happened

CenterPoint learned of an online post claiming a customer dataset, investigated, and determined that personal information for a portion of customers had been obtained via an external-facing system. Electric and gas delivery continued. The company is working through notification obligations as forensics finish the affected population.

Threat actor reporting tied to handle “4d722e4d656f77” claimed roughly 7.49 million records were pulled via API enumeration without adequate rate limits or WAF controls. That technical story is actor/press narrative, not the SEC filing’s wording. Class-action complaints filed after the disclosure allege an access window on the order of mid-to-late August into early September — again, allegations, not company findings.

Timeline

  • ~August–early September 2026: Alleged access window in litigation narratives; actor posts circulate.
  • September 14, 2026: CenterPoint Form 8-K confirms unauthorized obtaining of customer personal information via an external-facing system.
  • September 15–16: Trade and local press amplify; customer FAQ guidance begins circulating; notifications pending full scope.

What data may be involved

Company-confirmed: personal information relating to a portion of customers (exact types under investigation at filing time).

Actor claim (unverified): names, phone numbers, email and billing/service addresses, account details, billing amounts, payment/autopay-related fields, and last-four Social Security numbers.

Do not merge those columns in your head. If your only source is the actor paste, you do not yet have a company field inventory. If CenterPoint later mails you a notice listing specific elements, that letter controls.

How the attack may have worked

The SEC filing points at an external-facing system — language consistent with a customer portal, API, or similar internet-reachable service. Actor claims of unauthenticated or weakly protected API enumeration are plausible for that class of system but remain unverified. Utilities are high-value targets because account data links real homes to identity and payment rails even when grid operations stay up.

Who is at risk

CenterPoint electric/gas customers in served territories — watch for official mail and portal messages.

Former customers whose records may still sit in billing systems.

Employees and call-center staff — expect phishing that spoofs “CenterPoint breach credit monitoring.”

What CenterPoint said

Customer personal information obtained for a portion of customers; external-facing system involved; energy delivery unaffected; investigation ongoing; notifications to follow. The company has not publicly endorsed the 7.49 million figure in the materials summarized for this catalog.

Was I affected?

If you are a CenterPoint customer and receive a company notice, follow it. If you only saw a dark-web screenshot with 7.49M in the headline, that alone does not prove your row was in a confirmed extract. Still harden accounts: utility portals are classic password-reuse targets after headlines.

What you should do

  1. Use only centerpointenergy.com links you type yourself.
  2. Enable MFA on your CenterPoint account if offered.
  3. Change the password if it was reused elsewhere.
  4. Watch for fake “SSN last-4 verification” calls.
  5. Consider a credit freeze if you later receive a notice listing SSN elements.
  6. Monitor bank accounts tied to autopay.
  7. Keep any official breach letter for disputes.
  8. Report utility-themed phishing to CenterPoint and your state AG.
  9. Employees: verify internal incident tickets out-of-band.
  10. Do not buy “CenterPoint full dump” archives from forums.

Canonical record and sources

CenterPoint Energy catalog entry

Evidence-folder note 1 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 2 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 3 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 4 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 5 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 6 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 7 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 8 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 9 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 10 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 11 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 12 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 13 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 14 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 15 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 16 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 17 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 18 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 19 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 20 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 21 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 22 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 23 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 24 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 25 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 26 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 27 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 28 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 29 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 30 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 31 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 32 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 33 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 34 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 35 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 36 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 37 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 38 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 39 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.

Evidence-folder note 40 for CenterPoint Energy: store the primary notice URL, the published impact statement, and any regulator or law-enforcement references together. Brief executives from those artifacts only. Update the BreachHistory catalog when the victim revises counts, confirms data types, or issues a restoration notice.