CenterPoint Energy Confirms Customer Data Breach
CenterPoint Energy confirmed an unauthorized party accessed personal data for some customers after a hacker posted claims of nearly 7.5 million records and a 2.5 GB archive.
CenterPoint Energy confirmed on Monday that an unauthorized third party obtained personal information for a portion of its customers after a hacker posted claims on Sept. 12 offering nearly 7.5 million records and a 2.5 GB archive for download.
In a filing with the U.S. Securities and Exchange Commission, CenterPoint reported it opened an investigation after becoming aware of the claim. The filing states the data was accessed through one of the company’s external-facing systems and that the incident has not affected delivery of electric or gas services.
The Houston-based utility delivers electricity and natural gas to about 7 million customers in Indiana, Minnesota, Ohio and Texas. The company indicated in the filing it does not expect the incident to have a material impact on operations.
The hacker posted on a cybercrime forum on Sept. 12 and made available a 2.5 GB archive alleged to contain the stolen records. The post included a threat: “next time we won’t simply pull data, we’ll start attacking the main infrastructure.” Security researchers warn that the authenticity and scope of such data dumps are often difficult to verify and that threat actors sometimes exaggerate their access.
CenterPoint did not provide a count of affected customers or list the types of personal information exposed in the SEC filing. The company said the investigation remains ongoing as it works to determine the extent of the access and the source of the data.
CenterPoint has faced similar claims previously. In 2024 it was identified among energy-sector targets linked to an access broker known as AntiBrok3rs, and another actor later claimed to have obtained CenterPoint records. Analysts tracking those incidents linked the reports to the Cl0p ransomware group’s 2023 exploitation of a vulnerability in MOVEit file transfer software and noted many reported exposures stemmed from third-party vendors rather than direct intrusions into corporate networks.
Federal and state rules generally require companies to notify individuals when personal data is confirmed stolen. CenterPoint has not yet announced details on notifications or customer remediation. The company reiterated that its systems continue to supply electricity and gas while it coordinates a response.







