CenterPoint Energy Confirms Customer Data Stolen After Hacker Posts 7.5 Million Records Online

A Houston electricity and gas supplier serving 7 million households has told federal regulators that an outsider broke into one of its internet-facing systems and walked off with customer personal information.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Full-frame edge-to-edge photoreal news-editorial image of a darkened modern data center corridor with rows of server racks, soft blue and amber indicator lights
Share

Key points

  • CenterPoint Energy, a Houston-based utility serving roughly 7 million customers, confirmed a data breach in an SEC filing on Monday.
  • A hacker claimed on September 12 to have stolen nearly 7.5 million customer records and posted a 2.5 GB download archive on a criminal forum.
  • The same hacker threatened to attack CenterPoint's physical infrastructure in any future incident.
  • Power and gas delivery hasn't been affected, and the company says it doesn't expect significant financial harm.
  • This is at least the third time hackers have claimed to hold CenterPoint customer data, though the two earlier incidents were traced to a third-party software supplier, not CenterPoint itself.

CenterPoint Energy, which supplies electricity and natural gas to homes and businesses across Indiana, Minnesota, Ohio, and Texas, has confirmed that criminals broke into one of its externally accessible computer systems and took personal information belonging to some of its customers.

The company disclosed the breach in a filing with the SEC (the U.S. Securities and Exchange Commission, which requires publicly traded companies to report significant incidents). It said an investigation is underway and that it became aware of the breach after a hacker publicly claimed to have the data.

How did this come to light?

A criminal posted the stolen data on a well-known cybercrime forum on September 12, offering a 2.5 GB archive file for download. The post claimed the haul contained nearly 7.5 million customer records. SecurityWeek, which first reported the forum posting, noted it couldn't independently verify the contents.

The hacker also issued a blunt warning: the next intrusion would go beyond copying data and would target CenterPoint's operational infrastructure, meaning the systems that actually control the flow of electricity and gas. CenterPoint said no such disruption has occurred.

Should customers be worried?

Yes, practically speaking. The company hasn't said what types of personal information were taken, so the specific risk is still unclear. That uncertainty is itself the problem.

If your name, address, account number, or email address was in those records, it could be used to impersonate you or craft a convincing phishing message, where criminals send a fake email or text that looks official to trick you into handing over passwords or bank details. Watch for unexpected contact claiming to be from CenterPoint asking you to verify details or pay a bill through an unfamiliar link. Call the number on your utility bill directly if something feels off.

Date Event
2023 Cl0p ransomware group's MOVEit campaign; CenterPoint data believed exposed via a third party
2024 Access broker AntiBrok3rs claims CenterPoint access; separate hacker makes second claim
September 12, 2025 Hacker posts alleged 7.5 million-record archive on cybercrime forum
Monday (this week) CenterPoint confirms breach in SEC filing

This is the third time in roughly two years that criminals have claimed to hold CenterPoint customer data. The first two incidents, in 2023 and 2024, were tied to the Cl0p ransomware group's attack on MOVEit, a widely used file-transfer tool. In those cases, analysts believed the data came from a third-party company CenterPoint shared information with, not from CenterPoint's own systems. This latest incident appears to involve CenterPoint's own internet-facing systems directly.

That distinction matters. A supplier breach is largely outside a utility's control. A breach of your own external systems isn't.

We covered a similar pattern on 9 September, when Veradigm confirmed attackers used a vendor's stolen login to reach a customer-service API. The question CenterPoint now faces is more uncomfortable: whether stronger access controls or multi-factor authentication (MFA, which requires a second proof of identity beyond a password) on that external system would have prevented this. Given that two prior incidents already circled this company's data, the investigation owes customers a straight answer on that point.

© 2026 Threat Vectr