CenterPoint Energy disclosed in an SEC 8-K filing that an attacker accessed customer personal information through an internet-facing system after the utility identified a dark-web post offering alleged CenterPoint data. The company said the investigation confirmed unauthorized access affecting an undetermined number of customers, while the threat actor claimed to possess roughly 7.5 million records containing names, contact details, account and billing information, service data, and the last four digits of Social Security numbers. CenterPoint has not confirmed the actor's claimed record count or full dataset, and electricity and natural-gas operations were not disrupted.
The Houston-based utility reported the incident to law enforcement and is engaging third-party specialists to establish its scope and issue required notifications. It also faces five proposed federal class-action suits; three allege its guest bill-pay feature exposed personal information when users entered account numbers, though those allegations have not been established in the company's disclosure.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
A hacker claiming to have stolen nearly 7.5 million CenterPoint customer records posted an alleged 2.5 GB archive on a cybercrime forum and threatened that future activity would target the utility's main infrastructure. The validity and scope of the purported dataset had not been independently verified.
A threat actor using the handle “4d722e4d656f77” claimed to have leaked a CenterPoint database containing roughly 7.49 million raw JSON records and 6.73 million filtered CSV records, and provided sample data.
CenterPoint previously investigated a separate incident involving customer information stolen through a file-sharing platform.
CenterPoint reported the incident to law enforcement and engaged third-party experts to determine the affected customers and data. The company said electric and natural-gas delivery was not disrupted and that required notifications would be made.
CenterPoint disclosed in an SEC 8-K filing that attackers obtained customer personal information from an internet-facing system after the company became aware of a dark-web post offering purportedly stolen data. It did not confirm the claimed 7.5 million-record volume or precise data set.
Five proposed federal class-action lawsuits were filed over the alleged breach, including three brought by Shamis and Gentile and two by Lippe and Associates. The suits alleged inadequate security and sought damages related to identity-theft and fraud risks.
Subsequent lawsuits alleged that cybercriminals accessed CenterPoint customer names, contact and billing information, and Social Security-number data during an incident placed between August 17 and September 1. Three complaints alleged the online guest bill-pay feature was the access vector.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcetherecord.media
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.