CenterPoint Energy disclosed a data breach after an unauthorized third party obtained personal information from some of its customers through an internet-facing company system.
The Houston-based utility company revealed the incident in a Form 8-K filing with the U.S. Securities and Exchange Commission on September 14, 2026.
CenterPoint said it learned of an online post from a third party claiming to have a dataset containing customer information. The company said it immediately activated its cybersecurity incident response procedures after discovering the alleged data exposure.
CenterPoint also launched an investigation with external cybersecurity experts and implemented additional measures to protect its systems.
According to the filing, the company has confirmed that an unauthorized party accessed personal information connected to a portion of its customer base.
However, CenterPoint has not yet disclosed how many individuals were affected, what categories of personal data were exposed, or the attacker’s identity.
CenterPoint Energy Data Breach
The investigation remains ongoing, and the company is working with third-party incident response specialists to determine the full scope of the breach. This includes identifying which customers were affected and exactly what information was taken from the exposed external-facing system.
CenterPoint said it intends to notify impacted customers and regulatory authorities where required under applicable data breach notification laws. The utility has also reported the matter to law enforcement and notified certain regulators.
The company emphasized that its electric and gas delivery operations have not been affected by the cybersecurity incident. Service delivery remains operational and undisrupted, suggesting that the attackers accessed a customer-related system rather than systems responsible for operational technology, grid management, or gas distribution.
This distinction is important because energy companies operate critical infrastructure environments where cyber incidents can create risks beyond data exposure. A breach affecting operational technology could potentially disrupt electricity or gas delivery.
At the same time, a compromise of customer-facing or business systems may expose personal information, billing records, account details, or contact data.
CenterPoint did not provide technical details about the external-facing system involved in the incident. The filing also did not confirm whether the access resulted from exploited software vulnerabilities, stolen credentials, weak authentication controls, cloud misconfiguration, or another intrusion method.
External-facing systems are common targets for threat actors because they can be accessed from the internet. Attackers often scan these environments for unpatched vulnerabilities, exposed remote access services, leaked login credentials, improperly configured storage platforms, or application security flaws.
The utility said it has incurred incident response costs and expects additional expenses as its investigation continues. These expenses may include forensic analysis, legal review, regulatory notifications, customer communications, security improvements, and potential identity protection services for affected customers.
CenterPoint said it maintains customary cybersecurity insurance and believes the coverage will help offset breach-related costs. At this stage, the company does not believe the incident is reasonably likely to have a material impact on its financial condition or operating results.
The company warned, however, that the scope of the breach could be greater than currently known. Its ongoing review will determine the extent of exposed customer data, remediation requirements, regulatory obligations, insurance recovery, and the incident’s long-term impact.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

