CenterPoint Energy Confirms Customer Data Stolen in Cyberattack
Utility company discloses breach after attacker leaks allegedly stolen customer information

Key Takeaways
- CenterPoint Energy confirmed a data breach compromising some customers' personal information.
- An attacker leaked data allegedly stolen from the company, indicating data exfiltration.
- The full scope of affected individuals and data types is not yet disclosed.
- The attack vector and attacker identity remain unconfirmed.
- Customers are advised to monitor accounts and change passwords as a precaution.
Quick answers
- What happened?
- CenterPoint Energy, a major U.S. utility provider, has confirmed a data breach that compromised some customers' personal information. The disclosure follows an attacker leaking data allegedly stolen from the company. The full scope of the incident remains unclear, and the company is advising customers to monitor their accounts.
- What should defenders do?
- Affected customers should monitor their financial accounts and credit reports for suspicious activity. Change passwords for online accounts, especially if reused across services. Enable multi-factor authentication where available. Be cautious of phishing emails or messages that may reference the breach. The company may offer credit monitoring services; customers should follow official communications from CenterPoint Energy.
CenterPoint Energy, a major American utility company, has confirmed that some customers' personal information was compromised in a cyberattack. The disclosure comes after an attacker leaked data allegedly stolen from the company, according to a report by BleepingComputer published on September 15, 2026.
The company acknowledged the breach but has not yet disclosed the full scope of affected individuals or the specific types of data involved. The initial attack vector remains unknown, and the identity of the attacker has not been verified.
CenterPoint Energy operates in multiple states across the U.S., but the report does not specify which regions are affected. The company is likely advising customers to monitor their accounts and change passwords as a precaution, though specific guidance has not been detailed.
This incident highlights the ongoing threat to critical infrastructure and utility providers, which hold sensitive customer data and are considered high-value targets for cybercriminals. While no ransomware or extortion demands have been publicly reported, the leak of stolen data suggests that exfiltration occurred.
As the investigation continues, affected customers should remain vigilant for potential phishing attempts or fraudulent activity. The company has not yet provided a timeline for further updates.
Security Details
CenterPoint Energy confirmed that some customers' personal information was compromised in a cyberattack. An attacker leaked data allegedly stolen from the company, indicating that data was exfiltrated. The exact method of intrusion and the full list of compromised data are not yet disclosed. The company has not provided specific mitigation steps beyond general advice to monitor accounts and change passwords.
Mitigation
Affected customers should monitor their financial accounts and credit reports for suspicious activity. Change passwords for online accounts, especially if reused across services. Enable multi-factor authentication where available. Be cautious of phishing emails or messages that may reference the breach. The company may offer credit monitoring services; customers should follow official communications from CenterPoint Energy.
Sources
BleepingComputer
CenterPoint Energy confirms customer data stolen in cyberattack
Sep 15, 2026 · 16:40
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

Bitget Reports $388M Loss Following Exploitation of Third-Party Security Product Flaw
Bitget disclosed that an attacker stole approximately $388 million by exploiting a vulnerability in a third-party security product integrated into the exchange's infrastructure. The threat actor used the flaw to obtain high-level internal credentials, which were subsequently used on September 24 to issue fraudulent withdrawal commands to Bitget's wallet system. The exchange confirmed that most user funds remain secure, though the full extent of exposure is under investigation.



