CenterPoint Confirms Breach as Hacker Leaks Data
CenterPoint Energy says an unauthorized third party obtained customer data after a hacker claimed to have stolen millions of records.
A hacker posted claims of a large data theft from a Houston-based utility, and days later the company told federal regulators that customer information had indeed been accessed. The sequence — public boasting first, corporate confirmation second — has become a familiar pattern in the energy sector, and it leaves customers and regulators piecing together what was taken.
CenterPoint Energy, which delivers electricity and natural gas to roughly 7 million customers, confirmed on Monday that a threat actor obtained customers' personal information. The company's disclosure followed a cybercrime forum post in which a hacker claimed to have stolen millions of records.
What the company has not done is confirm the scope of the leak, respond to the hacker's specific threats, or say what happens next for the people whose data may be involved.
What the filing actually says
CenterPoint told the SEC that it launched an investigation after becoming aware of someone claiming to have obtained customer information. In the filing, the company described the breach in deliberately narrow terms.
“While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external facing systems,” it said in the SEC filing.
— CenterPoint Energy, in its SEC filing
The utility said the cybersecurity incident has not affected the delivery of electric and gas services. It also said it does not believe the data breach will have a material impact. The filing does not identify how many customers are covered by the phrase “a portion of the Company’s customers,” nor does it describe what categories of personal information were involved.
The hacker’s claims on the forum
The company's disclosure came after a hacker leaked data allegedly stolen from its systems. The claims were made on a popular cybercrime forum on September 12.
According to the claims, the hacker obtained nearly 7.5 million user records and threatened that “next time we won’t simply pull data, we’ll start attacking the main infrastructure.” The threat actor made available for download a 2.5 GB archive file allegedly containing data stolen from CenterPoint Energy.
SecurityWeek cannot confirm the validity of the data, and it’s not uncommon for hackers to make false or exaggerated claims. The gap between the hacker’s assertion of millions of records and the company’s description of “a portion” of customers remains unresolved in public statements from either side.
A repeat target with a tangled history
This is not the first time a hacker has claimed to have stolen CenterPoint Energy data. In 2024, the company was one of several energy companies targeted by an access broker named AntiBrok3rs.
A few months later, a different hacker claimed to have obtained the company’s data. In both cases, the stolen data was believed to have come from the Cl0p ransomware group’s 2023 MOVEit campaign. Analysts believed at the time that the CenterPoint Energy data originated from a third party rather than directly from the company’s systems.
That history matters when evaluating the current claim. Previous incidents involving the utility were traced to a vulnerability in third-party file-transfer software rather than a direct intrusion into CenterPoint’s own network. The company’s current filing, however, points to “one of the Company’s external facing systems” as the vector — a description that leaves open whether the exposure came through a vendor, a portal, or another connected service.
What the company has confirmed — and what it hasn’t
CenterPoint's public position rests on three statements: that an unauthorized third party obtained personal information belonging to a portion of its customers, that service delivery was not affected, and that the breach is not expected to have a material impact.
Beyond that, the filing is silent on several practical questions. It does not specify how many customers are affected, what types of personal information were accessed, or when the unauthorized access occurred. The company has not said whether it will notify affected individuals, whether it plans to offer credit monitoring, or what internal changes it might make to the external system involved.
SecurityWeek cannot independently verify the hacker's claim of 7.5 million records, nor can it confirm the contents of the 2.5 GB archive. The company's own characterization — “a portion of the Company’s customers” — does not specify whether that portion is measured in thousands, hundreds of thousands, or millions.
The numbers in play
- Roughly 7 million customers across Indiana, Minnesota, Ohio, and Texas are served by CenterPoint Energy.
- The hacker claimed to have obtained nearly 7.5 million user records.
- The archive offered for download was 2.5 GB.
- The forum claims were posted on September 12.
- CenterPoint confirmed the breach on Monday.
- In 2024, CenterPoint was one of several energy companies targeted by an access broker named AntiBrok3rs.
- A 2023 MOVEit campaign by the Cl0p ransomware group was believed to be the source of data in earlier claims against the company.
Why the SEC filing matters
CenterPoint chose to disclose the incident through a regulatory filing rather than a standalone customer announcement. That choice shapes what the public knows: the filing language is legalistic and narrow, focused on what the company has determined so far and what it believes the financial consequences will be.
The company said the investigation remains ongoing. That means the description of the incident — “an unauthorized third party obtained personal information relating to a portion of the Company’s customers” — is the company’s current understanding, not necessarily its final one. Investigations into data theft often expand as forensic work proceeds, and the categories of data involved can take weeks or months to fully catalog.
For now, the filing stands as the company’s only detailed public statement on the matter. It confirms the breach occurred while leaving the scale, the data types, and the response plan largely unspecified.
The threat that goes beyond data
The hacker's forum post included a warning that went past the theft itself. The message threatened that “next time we won’t simply pull data, we’ll start attacking the main infrastructure.”
CenterPoint's filing states that the incident has not impacted the delivery of electric and gas services. That is a point-in-time assessment, not a guarantee about future attempts. The utility operates infrastructure that serves millions of homes and businesses across four states, and the company's own disclosure acknowledges an external-facing system was compromised.
Whether the hacker has the capability or intent to follow through on the infrastructure threat is unknown. SecurityWeek cannot confirm the validity of the data or the credibility of the threat. What is documented is the claim itself and the company's confirmation that unauthorized access to customer information took place.
What readers should watch for
For CenterPoint customers, the immediate practical question is whether their personal information was among the data involved — and the company has not yet answered that. Customers in Indiana, Minnesota, Ohio, and Texas who want clarity may need to wait for the company to complete its investigation and, if it chooses, issue notifications.
The filing provides no timeline for when more information might come. It also does not say whether the company will publish updates outside of required regulatory disclosures.
For security teams at other utilities and infrastructure operators, the incident is another data point in a pattern that has repeated around CenterPoint: claims surface on criminal forums, the company investigates, and the public learns details in stages. The 2023 MOVEit campaign and the 2024 AntiBrok3rs activity both fed earlier claims against the same company, even when the data was believed to originate from third parties rather than its own systems.
That history suggests the current incident may also involve questions about third-party exposure — but the company's filing does not say so, and SecurityWeek cannot confirm it. What is clear is that the investigation is ongoing and the company's public accounting of the breach remains partial.
Sources
- SecurityWeek Original source
- AntiBrok3rs Also reporting
- claimed Also reporting
- MOVEit campaign Also reporting
Continue Reading
Swiss Court Jails Ransomware Coder 12 Years
A Zurich court found the 52-year-old Ukrainian developer built LockerGoga, MegaCortex, and Nefilim, though not as the operations' mastermind.
Malware Taps MQTT to Run Windows, Linux Bots
Lumen's Black Lotus Labs says BambooToken abuses the IoT messaging protocol and a signed banking token to control compromised hosts across Asia and South America.
Fake Hires Get Network Access First
A HYPR report finds most fraudulent hires receive corporate credentials before detection, leaving firms exposed to insider risk.