Data Breaches

Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems.

CenterPoint Energy data breach

Texas utility CenterPoint Energy confirmed on Monday that a threat actor has obtained customers’ personal information. The disclosure comes just days after a hacker claimed to have stolen millions of records.

CenterPoint Energy is a Houston-based public utility that delivers electricity and natural gas to roughly 7 million customers across Indiana, Minnesota, Ohio, and Texas.

The company told the SEC that it has launched an investigation after becoming aware of someone claiming to have obtained customer information.

“While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external facing systems,” it said in the SEC filing.

The utility noted that the cybersecurity incident has not impacted the delivery of electric and gas services and it does not believe that the data breach will have a material impact.

The company’s disclosure comes after a hacker leaked data allegedly stolen from its systems. The claims were made on a popular cybercrime forum on September 12.

Advertisement. Scroll to continue reading.

The hacker allegedly obtained nearly 7.5 million user records, threatening that “next time we won’t simply pull data, we’ll start attacking the main infrastructure.”

The threat actor has made available for download a 2.5 GB archive file allegedly containing data stolen from CenterPoint Energy. SecurityWeek cannot confirm the validity of the data and it’s not uncommon for hackers to make false or exaggerated claims.

CenterPoint Energy hacked

This is not the first time a hacker has claimed to have stolen CenterPoint Energy data. In 2024, it was one of several energy companies targeted by an access broker named AntiBrok3rs.

A few months later, a different hacker claimed to have obtained the company’s data. In both cases, the stolen data was believed to have come from the Cl0p ransomware group’s 2023 MOVEit campaign. Analysts believed at the time that the CenterPoint Energy data originated from a third party rather than directly from the company’s systems.

Related: 240,000 Hit by Data Breach at Japan’s Digital Agency

Related: Personal, Financial Info Exposed in Revolut Data Breach

Related: Telus Warns Customers of Account Breaches

Related Content

Data Breaches

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

Data Breaches

The company unintentionally disclosed users’ information to a third party impersonating a government agency.

Data Breaches

Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.

Data Breaches

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

Data Breaches

A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors.

Data Breaches

In June 2026, hackers stole personal, health, and insurance information from AdaptHealth’s systems.

Data Breaches

Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance.

Data Breaches

The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version