CenterPoint Energy Breach: Hacker Claims 7.49 Million Customer Records
Houston utility CenterPoint Energy confirmed in an SEC 8-K that an unauthorized third party obtained customer personal information through.

TL;DR
- —CenterPoint Energy supplies electricity and gas to roughly 7 million accounts across four states.
- —The suits place the breach window between August 17 and September 1, 2026.
- —A utility holding account numbers, addresses, and partial SSN data is a different breach from a consumer app because of what the information enables.
The Incident CenterPoint Energy supplies electricity and gas to roughly 7 million accounts across four states. In September 2026, a threat actor using the alias "4d722e4d656f77" posted on a dark-web forum (tracked originally on BreachForums) claiming to have extracted customer records from the utility — "well over 7.49 million" lines, delivered as JSONL and filtered CSV, in a 2.5 GB archive the actor offered for download. The company told the SEC it determined an "unauthorized third party obtained personal information relating to a portion of the Company's customers through one of the Company's external facing systems." It said electric and gas service delivery was not affected, and that it locked down systems, is investigating with third-party experts, and will notify affected customers, regulators, and law enforcement as required. What's Claimed Exposed The threat actor's claims include: Names, phones, service and billing addresses
Account numbers and billing amounts / payment status
Partial Social Security numbers
A technical claim (per Dark Web Intelligence's tracking) that data was pulled through an API the actor said lacked adequate authorization checks and rate limiting Separate reporting noted the actor's post also mentioned driver's-license information and move dates — though CenterPoint's official filing sticks to the generic "personal information," so category details from the forum post are not independently confirmed by the company. There's a legal dimension too: class-action filings against the utility were reported in federal court the week before the 8-K, alleging CenterPoint's online "guest bill pay" feature — which lets customers pay using only an account number — also returned a trove of personal data when the correct number was entered. The suits place the breach window between August 17 and September 1, 2026. Why Critical Infrastructure Data Matters A utility holding account numbers, addresses, and partial SSN data is a different breach from a consumer app because of what the information enables. Utility account records feed fraud that isn't just financial — they can unlock account takeover on essential services, and combined with addresses, they anchor sophisticated impersonation of both customers and, in the wrong hands, of the utility itself. There's also the actor's explicit threat: "next time we won't simply pull data, we'll start attacking the main infrastructure." A line like that should be taken seriously by any critical-infrastructure operator. When attackers hold both your customers' data and a demonstrated path into your external systems, data breach and infrastructure-attack risks converge — the same intersection we flagged when examining the API security crisis and the broader state of surveillance and critical-system defense. What to Do If you're a CenterPoint customer, assume the data is out. Watch for phishing that references your address, account number, or payment status — attackers will weaponize precisely this data.
Freeze your credit. With partial SSNs and account numbers in play, a credit freeze is cheap protection against identity fraud.
Beware utility impersonation. Real utilities send bills to your inbox; they don't call demanding immediate payment via gift card. Treat urgent "disconnection" calls with deep suspicion.
Don't click payment links in unsolicited messages. Log into your utility account directly from its official app or site instead of following emailed links. The Pattern CenterPoint is the utility-corridor echo of a theme that keeps returning: external-facing convenience features (guest pay, self-service portals) become the attack surface for the most sensitive data a company holds. The lesson for customers is familiar — freeze credit, expect phishing, verify before you pay. The lesson for infrastructure operators is starker: when an entity holds data that can both defraud customers and be parlayed into infrastructure threats, the cost of a weakly guarded external API stops being a consumer-privacy problem and becomes a public-safety one.