Cyber & AI intelligence
Wasteland.
Briefs indexed2601
Issues28
Published Mondays07:30 CT
▣ Breach CENTERPOINT-ENERGY 2026-09-15

CenterPoint Energy: Customer Data Taken Through an External System

"CenterPoint Energy, the Houston-based utility that serves roughly seven million metered electric and natural gas customers across Indiana, Minnesota, Ohio and Texas, has confirmed in a filing with the U.S. Securities…"

CenterPoint Energy, the Houston-based utility that serves roughly seven million metered electric and natural gas customers across Indiana, Minnesota, Ohio and Texas, has confirmed in a filing with the U.S. Securities and Exchange Commission that an unauthorized third party obtained personal information belonging to some of its customers. Reuters reported the disclosure on September 14, 2026, and UA.News, citing Channel NewsAsia's relay of the Reuters report, adds that the company traced the exposure to "one of its external systems" rather than its core network. The disclosure follows a September 1 post by a threat actor using the handle "4d722e4d656f77," who claimed to have leaked a CenterPoint customer database. Claimed record counts vary widely by source: Claim Depot puts the leak at approximately 7.49 million raw JSON records and 6.73 million filtered CSV records, while the class action complaints summarized by teiss cite 7 million filtered records in one filing and approximately 6.7 million affected customers in another. CenterPoint itself has not published a record count.

What Happened

The public timeline begins on September 1, 2026, when the actor posted on an open web forum claiming to have exfiltrated a CenterPoint customer database, reportedly including sample data and download links. Dark web monitoring accounts amplified the claim over the following days; Undercode News, writing on September 12, noted that the widely shared @DailyDarkWeb alert it examined was extremely thin, naming only the country and the company without dataset size, actor attribution, or company confirmation. That is worth stating plainly: much of the early "intelligence" circulating on this incident traced back to a single short social media post.

CenterPoint's own account, as reported through the SEC filing, is that the company became aware in September of the online post claiming to hold a dataset of customer information, then activated its cyber incident response protocols, engaged third-party cybersecurity specialists, and took additional steps to protect its systems. The investigation concluded that a third party had obtained personal data relating to some customers without authorization. The company states that electric and gas delivery services were not affected and remain operational, that it does not believe the incident is reasonably likely to have a material effect on its financial condition or results of operations, and that it has already incurred response costs and expects more, with cyber risk insurance expected to cover related expenses.

Accounts differ on the entry point. A summary of CenterPoint's SEC disclosure published by Ainvest frames the investigation as tied to the 2023 MOVEit file transfer vulnerability, quoting a company spokesperson saying "we have no reason to believe that our network was compromised" and stating that CenterPoint was examining whether the data came from a third-party vendor's system. No other source in this set makes the MOVEit connection, and the MOVEit framing would place the origin of the data three years before the leak post. Treat it as an unconfirmed single-source claim. What the better-corroborated reporting supports is narrower: the data came from an external system, and CenterPoint has not said its internal network was breached.

Litigation moved faster than confirmation. teiss reported on September 14 that five proposed class actions were already pending in federal court: three filed by Florida firm Shamis and Gentile on behalf of customers Laurie Eirwin, Latoya Wyche and Christa Floyd, and two by Dallas firm Lippe and Associates for Joyce Curry and Nathaniel Sonia, with plaintiffs resident in Indiana, Texas and Minnesota. No class has been certified. The complaints place the incident window between August 17 and September 1, 2026, and, as filed, acknowledged that CenterPoint had not verified the breach. The Shamis and Gentile complaints reportedly focus on CenterPoint's online account system and specifically its guest bill pay function. At least one additional firm, Edelson Lechtzin, announced an investigation on September 10.

What Was Taken

CenterPoint's SEC language is generic: personal information relating to some customers. The detailed field list circulating publicly comes from the actor's own posting and the dark web summaries built on it, reproduced almost verbatim by Claim Depot and Edelson Lechtzin. Those describe customer names, phone numbers, service and billing addresses, account information, premise IDs, billing amounts, payment status, service details, autopay and paperless billing status, and partial Social Security numbers.

Volume claims, attributed:

The clustering around 6.7 to 7.5 million is consistent with the company's roughly seven million metered customers, which makes the claim plausible in scale but does not independently verify it. One caution on sensitivity: the class action complaints allege exposure of "Social Security numbers" without the "partial" qualifier used in the actor's own description, and the Claim Depot page carries a checklist naming dates of birth, government IDs and medical information that does not match its own article text and reads as site boilerplate rather than incident-specific finding. Do not treat full SSNs, dates of birth, or medical data as confirmed exposed.

Even on the conservative reading, this is a high-quality fraud dataset. Name plus verified service address plus account number plus premise ID plus current balance and autopay status is exactly the package needed to impersonate a utility in a shutoff scam, and partial SSNs are useful for clearing the knowledge-based authentication checks used by call centers at other institutions.

Why It Matters

The operational grid was not touched, and CenterPoint says so clearly. The significance sits elsewhere.

First, this is a customer-data incident at critical infrastructure, and the distinction between IT and OT does not make the stolen data harmless. Billing records reveal which addresses are on medical-necessity or life-support programs, which are in arrears, and which are commercial accounts, all of which support targeting for social engineering, extortion, and follow-on intrusion, as Undercode News notes in general terms about energy sector data exposure.

Second, the external system angle is the recurring lesson. If CenterPoint's position holds, the customer data left through a peripheral or vendor-adjacent platform while the corporate network stayed intact. That is the dominant shape of large consumer data loss in 2026: not a domain compromise, but an internet-facing billing portal, guest payment flow, or managed file transfer appliance quietly hemorrhaging records. The plaintiffs' focus on guest bill pay points in the same direction.

Third, the disclosure sequence is instructive for incident response planning. A forum post on September 1 produced five federal complaints and multiple law firm investigations before the company confirmed anything on approximately September 14. Roughly two weeks of silence became the narrative vacuum that leak-site summaries and litigation marketing filled, and several of the "facts" now in circulation about this breach originate from those pages rather than from CenterPoint or a regulator.

The Attack Technique

Nothing about initial access has been confirmed by CenterPoint, and there is no credible technical detail in the public record. What exists:

The honest summary is that the exfiltration method is unknown. Two mutually inconsistent stories are in circulation, one pointing at a 2023 third-party file transfer compromise and one at a 2026 web application flaw in a customer-facing payment path, and the available sourcing cannot resolve them.

What Organizations Should Do

  1. Inventory every internet-facing system that can return customer records without an authenticated session. Guest bill pay, order lookup, and "check my status" flows are the classic blind spot because they deliberately trade authentication for convenience. Test them for enumerable identifiers such as account numbers and premise IDs, and rate-limit and monitor them as if they were an API, because they are one.
  2. Instrument for bulk read, not just for intrusion. Six to seven million records leaving through a legitimate application path will not trip EDR. Set volumetric baselines and alerting on record counts per session, per IP, and per endpoint at the application and database layers.
  3. Re-audit third-party and legacy file transfer exposure. Whether or not the MOVEit thread holds here, 2023-era managed file transfer data is still surfacing on forums in 2026. Know which vendors held your customer data three years ago and what was ever staged there.
  4. Compress the time between external claim and internal answer. Pre-build the workflow that takes a leak forum post to a sample-data validation against your own records within days, and pre-draft holding statements. The two-week gap is where litigation and misinformation form.
  5. Harden call center and customer support identity verification against exactly this dataset. Anything derivable from a bill, including account number, premise ID, balance, and last payment, must stop functioning as proof of identity, and partial SSN should not clear authentication on its own.
  6. Warn customers directly and specifically. Billing-derived data makes very convincing shutoff and refund lures. Tell customers what your company will never ask for by phone or SMS, and publish the official notification channel so that scam messages are easier to spot.
  7. Track disclosure obligations on the assumption the figure grows. State attorney general filings and notification letters had not publicly appeared as of Claim Depot's September 8 report, and the confirmed scope may still be materially larger or smaller than the actor's claim.

Sources: CenterPoint Energy discloses customer data breach in SEC filing Re... | CenterPoint Energy Data Breach Exposes 7.49M Records | CenterPoint Energy Data Breach Investigation - Claim Depot | teiss - News - CenterPoint Energy faces class actions over alleged... | CenterPoint Energy Data Breach: Edelson Lechtzin LLP Launches Inves... | CenterPoint Energy Data Leak Raises Fresh Concerns Over Sensitive I... | Centerpoint Energy - Activates cybersecurity response and initiates... | CenterPoint Energy reports customer data breach in the United State...