2026 CenterPoint Energy — SEC confirms customer PII via external system; actor claims ~7.49M (unverified count)
Data compromised
Company: personal information for a portion of customers (types still under investigation). Actor claim (unverified): names, phones, emails, service/billing addresses, account numbers, billing amounts, payment/autopay fields, last-four SSNs
Technical writeup
Verified CenterPoint Energy Form 8-K — September 14, 2026. Company learned of an online post claiming a customer dataset; investigation determined an unauthorized party obtained personal information relating to a portion of customers via an external-facing system. Electric/gas delivery unaffected; customer notifications pending as scope is finalized. Threat actor “4d722e4d656f77” claimed ~7.49 million records exfiltrated via API enumeration without rate limits/WAF (BleepingComputer / Cyberinsider); that census and field list are not company-attested. Class actions allege access window ~Aug 17–Sep 1. recordsAffected 0 (no company census yet); companyConfirmed true.
Root cause
Unauthorized third party obtained customer personal information through an external-facing CenterPoint system (SEC 8-K). Actor alleged unauthenticated/weakly protected API ID enumeration.
References
- https://www.bleepingcomputer.com/news/security/centerpoint-energy-confirms-customer-data-stolen-in-cyberattack/
- https://cyberinsider.com/centerpoint-energy-confirms-data-breach-after-hacker-claims-7-49m-records/
- https://www.reuters.com/legal/litigation/centerpoint-energy-discloses-customer-data-breach-sec-filing-2026-09-14/