---
title: "CenterPoint Energy Confirms Breach After Hacker Claims 7.49M Records Stolen"
date: 2026-09-16
author: "Sofia Ramirez"
featured_image: "https://sqmagazine.co.uk/wp-content/uploads/2026/09/centerpoint-energy-data-breach-confirmation.jpg"
categories:
  - name: "Cybersecurity"
    url: "/cybersecurity.md"
tags:
  - name: "News"
    url: "/tag/news.md"
---

# CenterPoint Energy Confirms Breach After Hacker Claims 7.49M Records Stolen

CenterPoint Energy confirmed on September 14, 2026 that an unauthorized third party stole customer data through one of its external-facing systems. The Houston utility serves about 7 million accounts across Texas, Indiana, Minnesota, and Ohio.

## What to Know?

- CenterPoint Energy (NYSE: CNP) disclosed the breach in a Form 8-K filed with the SEC.
- A hacker using the alias “4d722e4d656f77” claims to have pulled 7.49 million customer records from an exposed API.
- Exposed fields allegedly include names, phone numbers, billing addresses, account numbers, and partial Social Security numbers.
- CenterPoint says electric and gas delivery were not disrupted and it does not expect a material financial impact.
- The company already faces multiple class action lawsuits filed by customers in several states.

## How It Happened?

The hacker claims to have exploited a public-facing API that had no web application firewall, no rate limiting, and no authentication token, pulling customer records in bulk before a CAPTCHA control interrupted the extraction. In the forum post, the actor wrote that the target “**lacked proper WAF protection, rate limiting, certification protection, and no JWT/Auth token to pull said data.**” CenterPoint’s [Form 8-K filing](https://www.sec.gov/Archives/edgar/data/1130310/000110465926107560/tm2625326d1_8k.htm) does not name the attacker, confirm the **7.49 million** figure, or list the exact fields exposed. It states only that “**an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external-facing systems.**“

> ‼️🇺🇸 Another forum post for CenterPoint Energy  
>   
> 🚨🇺🇸 CenterPoint Energy breach actor publishes full context on alleged 6.7M-customer data theft  
> ⠀  
> CenterPoint Energy is a major U.S. electric and natural gas utility serving customers across several states, including Texas and… <https://t.co/zi0zZwR4Ss> [pic.twitter.com/gP0l0FlzPU](https://t.co/gP0l0FlzPU)
> 
> — Dark Web Informer (@DarkWebInformer) [September 15, 2026](https://x.com/DarkWebInformer/status/2100010197066588385?ref_src=twsrc%5Etfw)

 ## The Claimed Scope

Posting on a cybercrime forum on September 12, the actor described splitting the stolen data into seven JSONL files plus a CSV that keeps the full personal information intact, and said a CAPTCHA cut the extraction short of a claimed **17.44 million** total. The company has not verified that number, and outside outlets have not fully authenticated the [leaked dataset](https://sqmagazine.co.uk/what-happens-data-breach/). Threat actors regularly inflate figures or repackage older breaches as new ones, so the confirmed scope could still move once CenterPoint’s investigation closes.

The attacker also warned that a future attempt would target “**the main infrastructure**” rather than just data. Utilities take that kind of line seriously even when it reads as forum bravado, since the same access that pulls customer records can sometimes be a step toward operational systems.

## Industry Pattern

In the same post, the hacker called out CenterPoint’s size directly, writing that it was “**quite funny to think a $26.2 billion company has WEAK protection.**” That figure is the attacker’s own claim, not one CenterPoint or the SEC filing confirms, but the underlying point tracks a familiar theme in utility breaches: the failure sits in an internet-facing API, not in the operational systems that keep power and gas flowing. The gap between a large regulated utility and an API with no rate limiting or token checks is the detail regulators and plaintiffs’ attorneys are likely to focus on next.

## What’s Next?

This breach follows a pattern common to critical infrastructure operators: an internet-facing API without basic guardrails becomes the easiest way in, while the utility’s core service, keeping the lights and gas on, stays untouched. The mismatch between a large, regulated utility and an unauthenticated data endpoint is the real story here, and it raises questions about how many other systems at the same company were built the same way.

**What’s Next**: Customers should watch for [phishing](https://sqmagazine.co.uk/voice-phishing-statistics/) and fake billing messages that reference real account details, since partial Social Security numbers and billing amounts can make a scam message look legitimate. CenterPoint says it will notify affected customers and regulators as required by law. Anyone contacted by the company should verify the request through official channels before clicking links or sharing more information, and should check account statements and credit reports for unfamiliar activity in the coming weeks.