CenterPoint Energy has confirmed that customer personal information was stolen in a cyberattack, following claims from a threat actor who leaked data allegedly taken from the Houston-based utility. The company disclosed the incident in a filing with the U.S. Securities and Exchange Commission.

CenterPoint Energy provides electric and natural gas service to roughly 7 million metered customers across Indiana, Minnesota, Ohio, and Texas, and generates more than $9.3 billion in annual revenue.

According to the SEC filing, an investigation determined that “an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external-facing systems.” The filing does not name the attacker, specify how many customers were affected, or detail which data categories were exposed. CenterPoint said the incident has not disrupted electric or gas delivery and does not believe it will have a material impact on the business.

What the attacker claims

A threat actor using the alias “4d722e4d656f77” told BleepingComputer they stole 7.49 million customer records, including names, phone numbers, service and billing addresses, account numbers, billing amounts, and partial Social Security numbers. The actor later leaked the data, claiming CenterPoint had ignored their outreach.

The attacker said the records were obtained by iterating through millions of IDs on a public CenterPoint API that lacked rate limiting, web application firewall protection, or other controls against automated bulk access. Separately, the same claim surfaced on a cybercrime forum on September 12, where the hacker made a 2.5 GB archive available for download and threatened to target CenterPoint’s “main infrastructure” in a future attack. The authenticity of the leaked data has not been independently verified.

Response and legal fallout

CenterPoint said it has activated incident-response procedures, engaged third-party cybersecurity experts, hardened affected systems, and notified law enforcement and regulators. The company intends to notify impacted customers as required by law once the scope of the breach is confirmed.

Multiple proposed class-action lawsuits have already been filed in federal court on behalf of potentially affected customers, alleging the breach occurred between August 17 and September 1.

This is not the first time CenterPoint data has surfaced in criminal circles. In 2024, the company was named by an access broker, and separately by another actor, in incidents believed at the time to be tied to data exposed through Cl0p’s 2023 MOVEit campaign rather than a direct compromise of CenterPoint’s own systems.