Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data
CenterPoint Energy confirms customer data breach after hacker claims to have stolen 7.5 million records.
Summary
Texas utility CenterPoint Energy has confirmed a data breach after a hacker claimed to have stolen 7.5 million customer records. The company stated that an unauthorized third party obtained personal information from one of its external-facing systems. While the investigation is ongoing, CenterPoint Energy does not believe the incident will materially impact its services or operations.
Full text
Texas utility CenterPoint Energy confirmed on Monday that a threat actor has obtained customers’ personal information. The disclosure comes just days after a hacker claimed to have stolen millions of records. CenterPoint Energy is a Houston-based public utility that delivers electricity and natural gas to roughly 7 million customers across Indiana, Minnesota, Ohio, and Texas. The company told the SEC that it has launched an investigation after becoming aware of someone claiming to have obtained customer information. “While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external facing systems,” it said in the SEC filing. The utility noted that the cybersecurity incident has not impacted the delivery of electric and gas services and it does not believe that the data breach will have a material impact. The company’s disclosure comes after a hacker leaked data allegedly stolen from its systems. The claims were made on a popular cybercrime forum on September 12.Advertisement. Scroll to continue reading. The hacker allegedly obtained nearly 7.5 million user records, threatening that “next time we won’t simply pull data, we’ll start attacking the main infrastructure.” The threat actor has made available for download a 2.5 GB archive file allegedly containing data stolen from CenterPoint Energy. SecurityWeek cannot confirm the validity of the data and it’s not uncommon for hackers to make false or exaggerated claims. CenterPoint Energy hacked This is not the first time a hacker has claimed to have stolen CenterPoint Energy data. In 2024, it was one of several energy companies targeted by an access broker named AntiBrok3rs. A few months later, a different hacker claimed to have obtained the company’s data. In both cases, the stolen data was believed to have come from the Cl0p ransomware group’s 2023 MOVEit campaign. Analysts believed at the time that the CenterPoint Energy data originated from a third party rather than directly from the company’s systems. Related: 240,000 Hit by Data Breach at Japan’s Digital Agency Related: Personal, Financial Info Exposed in Revolut Data Breach Related: Telus Warns Customers of Account Breaches Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Root RCE Zero-Day in Cisco Secure Email Gateway Under Active ExploitationTelus Warns Customers of Account BreachesTrezor Says 347,000 Users Received Phishing Emails After Brevo HackUkrainian Conti Ransomware Developer Sentenced to 4 Years in US PrisonAnthropic Says Russian Hackers Used Claude AI to Automate Malware EvasionCybersecurity M&A Roundup: 33 Deals Announced in August 2026Widened Scan Turns Up Fourth Rogue Claude Cyber IncidentOrganizations Warned of Cisco Secure FMC Exploitation Latest News $1 Million Sandbox Challenge Uncovers Linux Kernel FlawsExein Secures $270M at $1.7B Valuation for Physical AI SecurityThai Broadband Provider Hacked via Fortinet VulnerabilityOpenAI Investigates Report Linking AI Agents to RubyGems Attack240,000 Hit by Data Breach at Japan’s Digital AgencyApple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety ConstraintsHacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveZero Networks has named Yossi Dagan as Chief Financial Officer.Manifold has appointed Joe Sullivan to its Board of Directors.Patrick McKinney has joined Turing as Chief Information Security Officer.More People On The MoveExpert Insights This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email