The CenterPoint Energy breach: what is confirmed, and what to do
CenterPoint has confirmed that an outsider took customer information through an external-facing system. The 7.49 million figure doing the rounds came from the person selling the data, not from the company. Here is the difference, why no website can check you against it, and what is worth doing while the investigation runs.
On 14 September 2026 CenterPoint Energy told the SEC that an unauthorised third party obtained personal information belonging to some customers through an external-facing system, and that gas and electricity supply was never affected. It has not said how many people are involved or which details were taken. Two weeks earlier a forum seller had claimed about 7.49 million rows including names, service addresses, phone numbers, account numbers, driver’s licence numbers and the last four digits of Social Security numbers — claims the company has not confirmed. The data has not been published, so it is not in any breach database and no site can look you up against it. Freeze your credit, put a PIN on your utility account, and treat any call about your bill as unverified until you ring back on the number printed on it.
What CenterPoint confirmed vs what the seller claims
The middle column is CenterPoint’s own account, from its SEC filing and statements to reporters. The right column is what the person selling the data says, plus what has been reported around it. They are kept apart on purpose: almost every number attached to this breach in headlines comes from the right column.
| Question | What CenterPoint has said | What is claimed or reported |
|---|---|---|
| That it happened | Confirmed. CenterPoint says an unauthorised third party obtained personal information belonging to some of its customers through an external-facing system. | A seller using the handle 4d722e4d656f77 posted the data on a hacking forum on 1 September 2026, ahead of any company statement. |
| When it was disclosed | A Form 8-K filed with the SEC on 14 September 2026. The company has not said publicly when the intrusion started, how long the system was exposed, or when it was detected. | The forum post predates the filing by two weeks; the first lawsuits were filed before it as well. |
| How many people | Not stated. CenterPoint says it is working with outside experts to determine the scope. | 7.49 million rows pulled, roughly 6.73 million after de-duplication, with a claim that the full table held about 17.4 million. Unverified. |
| What was taken | “Personal information” belonging to some customers. No field list has been published, and the company has not confirmed the categories below. | Names, phone numbers, email addresses, service and billing addresses, account and premise numbers, billed amounts and due dates, autopay and paperless status, rate class, driver’s licence numbers and the last four digits of Social Security numbers. |
| How they got in | Described only as an external-facing system. No further detail released. | An external API said to have had no authentication token, no rate limiting and no web application firewall in front of it. |
| Service disruption | None. CenterPoint says electric and gas delivery was not affected and stayed running throughout. | Not disputed. Nothing in the claim involves operational systems. |
| Letters and credit monitoring | CenterPoint says it will notify affected customers and regulators as required by law. As of 23 September 2026 it has not announced credit monitoring or a dedicated notice page. | Not applicable. |
| Lawsuits | Not addressed. The 8-K says the company found no reasonable likelihood of a material financial impact. | At least five proposed federal class actions were filed between 10 and 13 September 2026 for customers in Texas, Indiana and Minnesota, and at least one firm announced an investigation on 10 September. |
Sources: CenterPoint Energy Form 8-K, 14 September 2026; reporting by Help Net Security and CyberInsider (15–16 September 2026), the Houston Chronicle on the proposed class actions (13 September 2026), and a law-firm investigation notice of 10 September 2026. Status as of 23 September 2026.
1. What happened, in order
On 1 September 2026 someone offered CenterPoint customer data on a hacking forum, describing roughly 7.49 million rows taken through an external-facing interface. Law firms picked it up first: an investigation was announced on 10 September, and at least five proposed class actions were filed for customers in Texas, Indiana and Minnesota between 10 and 13 September. CenterPoint filed a Form 8-K with the SEC on 14 September confirming that an unauthorised third party had obtained personal information belonging to some of its customers through an external-facing system, and said that gas and electricity delivery was never affected. The order matters: the lawsuits arrived before the company’s own disclosure, which is why coverage of this breach reads as louder than the company’s account of it.
2. Why you may be in it without thinking of yourself as a customer
CenterPoint delivers electricity and natural gas to around seven million homes and businesses across Texas, Indiana, Minnesota and Ohio, and in much of that footprint it is the wires-and-pipes company rather than the brand on your bill. In deregulated parts of Texas you pick a retail electricity provider, but CenterPoint is the one that owns the meter, reads it and restores the line after a storm, so it holds the account and the service address regardless of whose logo is on the statement. If you have ever had the power connected at a Houston-area address, you have a record here whether or not you remember choosing the company.
3. What is claimed, and why the address is the part that matters
The seller’s field list runs to names, phone numbers, email addresses, service and billing addresses, account and premise numbers, what each customer was billed and when it was due, whether they are on autopay, their rate class, driver’s licence numbers and the last four digits of Social Security numbers. CenterPoint has not confirmed any of it. Even so, read what the categories describe: not a password dump, but a verified record of who lives where, reachable on which number, paying how much. A utility account is one of the few datasets where the address is current by definition, because the service only works at the place you actually are.
4. The honest answer to “am I affected”
There is no lookup for this one and there will not be until the data is published somewhere public, which it has not been. Nothing from this breach has reached the known breach databases that email checkers search, so a clean result tells you only that nothing has been indexed. The answer will arrive as a letter, once CenterPoint finishes working out whose records were in the file. Until then the useful assumption for a current or former CenterPoint customer is that your name, address and phone number are in circulation — which, inconveniently, is also true of most people regardless of this breach.
5. What is worth doing before the letter comes
Freeze your credit at Equifax, Experian and TransUnion; it is free, it blocks new accounts, and a claimed licence number is the kind of detail that makes it worth doing now rather than later. Set a passcode or PIN on your CenterPoint account if it offers one, so a caller cannot talk their way past the last four digits of anything. Change the password on your online account, and anywhere you reused it. Then read one bill carefully, so you know what a real one looks like: the account number, the due date, the payment methods it actually accepts. Our step-by-step breach checklist puts the rest in order.
6. The shut-off call, and why it will get better
The utility disconnection scam is old and it works: a caller says the power goes off within the hour unless a payment goes through now, by prepaid card or app transfer, and keeps the person on the line so they cannot check. What a breach adds is the opening — an account number read back to you, the amount of your last bill, the address on file. None of that proves who is calling. A real utility sends written notice before disconnection, never demands gift cards, and has no objection to you hanging up and calling the number on your own bill. Tell the older people in your household the same thing, because they get these calls most often and the details make the call very hard to dismiss.
7. Lawsuits, letters, and what actually changes for you
The class actions will take years, and the notification letters will arrive long before any of them resolve. Neither does anything about the underlying problem, which is that your name, home address and phone number are now a little more widely copied than they were in August — and were already published, for free, on dozens of people-search and data-broker sites that had nothing to do with this breach. That part you can actually change. Our guide to removing your home address from the internet covers how, and our guide to breach letters covers reading the notice when it lands.
Your service address is already published elsewhere
This breach is not searchable. The sites that list your home address, phone number and relatives are — and they are where a convincing call usually starts. PersProtect shows which of 499 broker and people-search sites publish you right now, checks your email against known breach databases, and files the removals.
Check my exposure — free →The CenterPoint Energy breach, answered
Am I affected by the CenterPoint Energy breach?
Nobody can tell you yet, including CenterPoint. The company has confirmed that an outsider got customer information out of an external-facing system, but it has not said how many people are involved or which accounts, and it is still working that out with outside investigators. The data has not been published anywhere public, so it is not in the breach databases an email check searches, and any site offering to look you up against this one is guessing. If you have had an electricity or gas account with CenterPoint in Texas, Indiana, Minnesota or Ohio, the honest position is to assume you may be in it and act accordingly, then wait for the letter that says so.
Is the 7.49 million figure real?
It is the seller’s number, not the company’s. Whoever posted the data on 1 September described pulling about 7.49 million rows, roughly 6.73 million of them unique, and claimed the underlying table held far more. CenterPoint has confirmed none of that. Rows are also not the same thing as people: one household can appear several times across service addresses, closed accounts and billing records. Treat 7.49 million as the ceiling of a claim rather than a count of customers, in the same way we read every attacker’s number.
Were Social Security numbers exposed?
The seller says the last four digits were in the data, along with driver’s licence numbers. CenterPoint has not confirmed either. The last four on their own will not let somebody open an account in your name, but they are the exact thing call centres use to prove you are you, which makes them useful to a caller who already has your name, address and account number. A driver’s licence number is more serious and worth treating as such if a letter later confirms yours was in it.
What does a utility breach actually expose that matters?
Your current address, and proof that you live at it. Most leaks hand over an email and a password; a utility account ties a real name to a real service address, a phone number and a payment history that shows the account is active. That combination is what makes a caller sound like they are looking at your file, and it is also the raw material that people-search sites trade in. The electricity supply is not the risk here. The address is.
I got a call about my CenterPoint bill. Is it a scam?
Assume so until you have hung up and called back. Utility shut-off scams were the most common version of this long before the breach: a caller says your power is hours from being cut, demands payment by prepaid card, app transfer or crypto, and refuses to let you call back. A real utility does not work that way, does not take gift cards, and will not disconnect a residential account over a single phone call. The breach only changes how convincing the opening line sounds, because the caller may know your account number and what you actually owe. Hang up, then dial the number printed on your paper bill or on your own account page.
Should I freeze my credit over this?
It is free, it takes about fifteen minutes at the three bureaus, and it is worth doing whether or not you turn out to be in this one. It stops a new account being opened in your name, which is the damage a driver’s licence number and a set of identity details enable. It does not affect your existing accounts, your credit score, or your ability to use the cards you already have, and you can lift it temporarily when you need to apply for something.
Can I join a class action, and will I get money?
Firms are already signing people up and it costs nothing to add your name, but there is no certified class and no settlement, and cases like this run for years before anyone is paid. What to avoid in the meantime is the message that arrives saying compensation is waiting and asking for your bank details or Social Security number to release it — that scam follows every large breach within weeks. When a real settlement opens, it appears on the official claim site, and we list the open ones.
Should I close my CenterPoint account or change my password?
Closing the account does nothing about data already copied, and you need the electricity. Changing the password on your online account is worth a minute anyway, especially if you used the same one elsewhere, and turning on two-factor authentication where the account offers it is worth another. Beyond that, the useful work is not on the utility account at all — it is on the address and phone number that this data ties together and that dozens of other sites already publish.
You can change your password. You cannot change your address.
See which people-search sites publish where you live, who you live with and how to reach you — free, in about a minute.
Run my free exposure scan →