CenterPoint Energy Confirms a Breach It Won't Fully Describe
Security / news
CenterPoint Energy Confirms a Breach It Won't Fully Describe
The utility's SEC filing doesn't say how many customers are affected; the 7.49 million figure comes only from the attacker's own dark-web post.
CenterPoint Energy told the Securities and Exchange Commission on Sept. 14 that an unauthorized third party obtained personal information from "a portion of the Company's customers" through an external-facing system, without saying how many customers, what data, or which system.
The Houston utility filed the disclosure under Item 8.01, "Other Events," rather than Item 1.05, the section the SEC reserves for cybersecurity incidents a company judges material. The filing states directly that CenterPoint "does not believe it is reasonably likely" the breach will have a material impact on its finances, and that it carries cybersecurity insurance it expects to offset the cost of the investigation. CenterPoint has not named the external-facing system involved, unlike a Cisco advisory CISA published the same month, which named the exact product and CVE behind its own deadline.
What the company says against what the attacker claims
A threat actor using the alias 4d722e4d656f77 posted a claim on a dark-web forum that it had taken 7.49 million customer records and published a sample. CenterPoint has not confirmed that count or the authenticity of the posted data, leaving two accounts of the same breach that do not overlap much:
| CenterPoint's filing | Attacker's claim | |
|---|---|---|
| Records affected | Not specified | 7.49 million |
| Data exposed | "Personal information" | Names, phone numbers, addresses, account numbers, billing amounts, partial Social Security numbers |
| Cause | "External-facing system" | A poorly secured API |
The Register reported the attacker's own description of the cause as a poorly secured API, a specific claim CenterPoint has not addressed. Asked whether it could verify the leaked data, the company told the outlet only that "our filing speaks for itself."
A gap in dates only the lawsuits are filling
CenterPoint's 8-K does not give a start or end date for the intrusion. Class-action complaints filed since the disclosure allege the attacker was inside CenterPoint's systems from Aug. 17 to Sept. 1, a window that, if accurate, means the company took at least two weeks after the intrusion ended to learn of it, and only through the attacker's own forum post rather than its own detection.
CenterPoint said it has activated its incident-response plan, hired outside cybersecurity firms, and notified law enforcement and regulators, the same sequence IDScan.net described after a 153-million-record driver's license breach traced to its platform on Sept. 8. The filing states that the company's "delivery of electric and gas services has not been impacted," and that customer and regulatory notifications will follow "per applicable law."
The second customer-data disclosure in two years
This is not CenterPoint's first breach notice. The company confirmed in a filing reported by The Record that a 2023 flaw in the MOVEit file-transfer software, exploited at vendor CLEAResult, had exposed roughly 3 million CenterPoint customer records. At the time, CenterPoint said the data came from "a third-party vendor's system" and that it had "no reason to believe" its own network was compromised. That distinction does not appear to apply this time: the new filing describes the exposure as coming through CenterPoint's own external-facing system, not a vendor's.
CenterPoint has not said when it expects to complete the investigation or notify the customers whose records may be among the 7.49 million the attacker claims to hold.
Sources
More in Security
- 01Cisco and Acronis Share a CISA Deadline, Not a Severity ScoreOne flaw needs no password and no user interaction, the other needs an attacker already logged in, and CISA gave federal agencies the same three days to fix both.
- 02Bransys ELD App Shipped With Hardcoded Login CredentialsCISA disclosed three flaws Sept. 17 in the trucking compliance app, including a hardcoded password a researcher says exposed live location and engine data from every connected truck on a subset of fleets.
- 03MikroTik Patches RouterOS Flaws Attackers Exploited FirstPoland's national CERT says attackers began exploiting the chained flaws on Sept. 2, a day before MikroTik shipped a fix, and more than 122,500 routers were still reachable a week later.
- 04Attackers Exploit a JFrog Artifactory Bug in Four DayswatchTowr says attackers began minting administrator tokens by abusing a default empty join key, CVE-2026-82329, within days of JFrog's own patch shipping.