CenterPoint Energy put the breach in an SEC filing before the rumor mill finished inventing a headcount.
In a Form 8-K dated September 14, 2026 (Item 8.01), the Houston-based electric and gas utility (NYSE: CNP) said that in September it became aware of an online post by a third party claiming to possess a dataset of certain customer information. The company activated incident-response protocols, brought in third-party cybersecurity experts, and took steps to further protect its systems.
While the investigation remains ongoing, CenterPoint determined that an unauthorized third party obtained personal information relating to a portion of its customers through one of its external-facing systems. Scope of customers and data types is still being determined. The company intends to notify affected customers and regulators as required, and it has reported the matter to law enforcement and notified certain regulators already.
What the 8-K does not confirm: a victim tally, field list, dwell time, or root cause. A threat actor posting as “4d722e4d656f77” has claimed roughly 7.49 million records from a company API with weak auth and rate limits, plus fields such as names, phones, emails, service/billing addresses, account identifiers, billing amounts, payment-related fields, and last-four SSN digits (per CyberInsider’s summary of the actor post). CyberMerge prints that as an actor claim. Company-confirmed count stays Undisclosed.
Operational and financial color from the filing and Reuters: electric and gas delivery remains operational and undisrupted; CenterPoint does not currently believe a material impact on financial condition or results of operations is reasonably likely; it has incurred and expects further response expenses and believes customary cybersecurity insurance will offset related costs. A company spokesperson told Reuters on Tuesday the filing “speaks for itself.”
POV: critical infrastructure operators still lose customer PII on internet-facing surfaces that never touch SCADA. Underwrite the confirmed external-facing compromise and the Undisclosed headcount — not the dump-site number. Primary: the September 14 8-K. Reuters and CyberInsider are secondary confirmations of the filing and the unverified actor claim.
Underwrite sheet — sourced only: unauthorized third party obtained personal information for a portion of customers via an external-facing system (8-K); investigation ongoing on scope/data types (8-K); service delivery unaffected (8-K/Reuters); no material financial impact currently expected (8-K); law enforcement + certain regulators notified (8-K); ~7.49M / field list = actor claim only (CyberInsider) — Undisclosed until CenterPoint confirms.
