CenterPoint Energy Confirms Hackers Grabbed Customer Data After Forum Leak
Texas-based utility CenterPoint Energy has confirmed that customer personal information was stolen after a hacker surfaced on a cybercrime forum last week boasting about a major data haul.
The Houston company, which supplies electricity and natural gas to around 7 million customers across Texas, Indiana, Minnesota, and Ohio, filed a disclosure with the SEC on Monday acknowledging that an unauthorised third party accessed customer data through one of its externally facing systems. The investigation is ongoing.
The hacker made their move publicly on September 12th, claiming to have lifted nearly 7.5 million user records and dropping a 2.5 GB archive file as supposed proof. The post came with a barely subtle threat: next time they would not stop at pulling data but would go after the underlying infrastructure. Whether that is genuine capability or cheap bluster is anyone's guess.
CenterPoint says the incident has not disrupted gas or electricity delivery and does not expect any material financial impact. The usual boilerplate, in other words, but not necessarily wrong.
The validity of the leaked data has not been independently verified. Exaggerated claims are common enough on cybercrime forums that scepticism is warranted, though the SEC filing confirms something real did happen.
This is not the company's first rodeo. In 2024, an access broker calling themselves AntiBrok3rs listed CenterPoint among several energy companies they claimed to have access to. Shortly after, another actor surfaced with similar claims. Both incidents were linked to fallout from the Cl0p ransomware group's 2023 MOVEit exploitation campaign, with analysts suggesting the data came through a third-party vendor rather than CenterPoint's own systems directly.
Whether this latest breach follows the same pattern or represents a fresh intrusion is what investigators are presumably trying to work out right now.