← BACK TO FEED
data breachcritical infrastructureransomwarecybercrimeenergy sector

CenterPoint Energy Confirms Hackers Grabbed Customer Data After Forum Leak

Texas utility CenterPoint Energy has confirmed a data breach after a hacker claimed to have stolen approximately 7.5 million customer records and leaked a 2.5 GB archive on a cybercrime forum. The company filed with the SEC, stating that an unauthorized third party accessed personal customer information through an external-facing system, though it does not believe the incident will have a material business impact. This is not the first time hackers have claimed to have stolen CenterPoint Energy data, with similar claims made in 2024 linked to the Cl0p ransomware group's MOVEit campaign.

Texas-based utility CenterPoint Energy has confirmed that customer personal information was stolen after a hacker surfaced on a cybercrime forum last week boasting about a major data haul.

The Houston company, which supplies electricity and natural gas to around 7 million customers across Texas, Indiana, Minnesota, and Ohio, filed a disclosure with the SEC on Monday acknowledging that an unauthorised third party accessed customer data through one of its externally facing systems. The investigation is ongoing.

The hacker made their move publicly on September 12th, claiming to have lifted nearly 7.5 million user records and dropping a 2.5 GB archive file as supposed proof. The post came with a barely subtle threat: next time they would not stop at pulling data but would go after the underlying infrastructure. Whether that is genuine capability or cheap bluster is anyone's guess.

CenterPoint says the incident has not disrupted gas or electricity delivery and does not expect any material financial impact. The usual boilerplate, in other words, but not necessarily wrong.

The validity of the leaked data has not been independently verified. Exaggerated claims are common enough on cybercrime forums that scepticism is warranted, though the SEC filing confirms something real did happen.

This is not the company's first rodeo. In 2024, an access broker calling themselves AntiBrok3rs listed CenterPoint among several energy companies they claimed to have access to. Shortly after, another actor surfaced with similar claims. Both incidents were linked to fallout from the Cl0p ransomware group's 2023 MOVEit exploitation campaign, with analysts suggesting the data came through a third-party vendor rather than CenterPoint's own systems directly.

Whether this latest breach follows the same pattern or represents a fresh intrusion is what investigators are presumably trying to work out right now.

READ NEXT
LockBit Claims US Bank Scalp With September Leak DeadlineRiver Bank Paid Ransomware Crew to Delete Stolen Data. Trust Them on That.ExfilSquad Claims Police Database Scalp as UK Public Sector Breach Spree Continues