HOUSTON — CenterPoint Energy has confirmed that an unauthorized third party obtained personal information belonging to a portion of its customers after the utility became aware of an online post claiming that a third party had obtained company customer data.
CenterPoint disclosed the incident in a Form 8-K filed with the U.S. Securities and Exchange Commission on September 14, 2026. The company said it became aware of the online post during September and promptly activated its cybersecurity incident response procedures.
CenterPoint also brought in third-party cybersecurity specialists and took additional steps to protect its systems while investigators worked to determine the scope of the intrusion.
The company confirmed that the unauthorized party obtained personal information through one of CenterPoint’s external-facing systems.
CenterPoint has not publicly identified the specific system involved, how the attacker gained access, how long that access may have existed, or the full categories of customer information exposed.
The investigation remains active.
CenterPoint said it is still determining how many customers were affected and exactly what personal information was obtained. The company intends to notify affected customers and regulators as required by law.
The company has also reported the incident to law enforcement and notified certain regulatory authorities.
One important distinction in the disclosure is that the breach did not disrupt CenterPoint’s delivery of electricity or natural gas.
According to the SEC filing, electric and gas services remain operational and undisrupted.
The distinction is significant for a utility provider.
Cyberattacks against energy companies can target several different parts of an organization. Some attacks focus on customer databases, online account portals, billing systems, or externally accessible applications. Others attempt to reach operational systems responsible for physical infrastructure.
External-facing systems are a common point of exposure because they must remain accessible from outside an organization’s internal network.
Customer portals, web applications, authentication services, application programming interfaces, and other internet-accessible services can become targets if attackers identify stolen credentials, software vulnerabilities, configuration errors, or weaknesses in access controls.
CenterPoint has not disclosed the technical method used in this incident, so the exact attack path remains unknown.
That detail will be important as the investigation progresses.
Determining how the attackers gained access will help establish whether the incident involved exploitation of a vulnerability, credential compromise, application-level access, third-party exposure, or another method.
The company also has not publicly confirmed claims circulating online concerning the total number of records involved or the specific categories of information allegedly contained within the stolen data.
Those claims should remain separate from what CenterPoint has formally confirmed.
The company’s SEC filing establishes that customer personal information was obtained, but the precise number of affected customers and complete data set remain under investigation.
That difference matters because criminal groups frequently publish large figures or extensive data descriptions before an affected organization has completed forensic analysis.
Until CenterPoint finishes that work, the confirmed scope remains limited to what the company has disclosed through its regulatory filing.
Customers potentially affected by the breach should be particularly cautious about follow-on phishing and impersonation attempts.
Once customer information is exposed, criminals can use names, account details, addresses, billing information, or other personal data to make fraudulent communications appear legitimate.
A message referencing a real utility account can be far more convincing than a generic phishing email.
Attackers may impersonate CenterPoint representatives, claim a payment is overdue, warn that service will be disconnected, request account verification, or direct customers toward fraudulent login pages.
Customers should independently access their CenterPoint accounts rather than using links contained in unexpected emails or text messages and should treat unsolicited requests for passwords, authentication codes, banking information, or full Social Security numbers with caution.
The risk can continue well after the original breach because stolen customer information can be stored, resold, combined with information from other breaches, and reused in future fraud campaigns.
CenterPoint’s investigation will also need to determine whether the compromised data can be used to facilitate identity theft or financial fraud.
That assessment depends heavily on the categories of information involved.
A breach containing basic contact information creates a different level of exposure from one involving government identifiers, financial records, authentication information, or account credentials.
CenterPoint has not yet provided enough information to make that determination.
The utility said it has already incurred expenses related to the investigation and expects additional costs as its response continues.
CenterPoint maintains cybersecurity insurance and said it believes that coverage will offset some of the expenses associated with the incident.
The company currently does not believe the incident is reasonably likely to have a material effect on its financial condition or operating results.
That assessment could change if investigators determine that the scope of the breach is greater than initially expected.
CenterPoint specifically acknowledged that possibility in its SEC filing, listing the potential for a larger-than-expected incident among the risks that could affect the final outcome.
The disclosure adds another cybersecurity incident to a sector that remains a high-value target because utilities maintain extensive customer databases while also operating infrastructure essential to daily life.
Even when utility service remains uninterrupted, the theft of customer information can create lasting consequences for individuals whose personal records enter criminal markets.
CenterPoint’s next disclosures will be critical in establishing the real scale of the incident.
For now, the confirmed facts are clear: an unauthorized third party gained access to an external-facing CenterPoint system, obtained personal information belonging to some customers, and triggered an investigation involving cybersecurity specialists, law enforcement, and regulators.
What remains unanswered is how the attackers entered the system, how much information they obtained, which customers were affected, and exactly what personal data was taken.
CenterPoint Energy, Inc. — Form 8-K filed with the U.S. Securities and Exchange Commission on September 14, 2026. (Free Download)
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



