CenterPoint Energy has disclosed a significant data breach where unauthorized access to customer information occurred through an internet-facing system. The Houston utility company brought this to light in a recent filing with the U.S. Securities and Exchange Commission on September 14, 2026, emphasizing the seriousness of the situation.
Discovery and Immediate Response
The breach was first identified after a third party claimed online possession of a dataset containing customer data. In response, CenterPoint swiftly activated its cybersecurity incident response protocols. The company has engaged external cybersecurity experts to assist in a comprehensive investigation and has implemented additional protective measures to secure its systems.
While the investigation is ongoing, CenterPoint confirmed that personal information from a segment of its customer base was accessed without authorization. However, they have yet to specify the number of customers affected, the types of data compromised, or the identity of the perpetrators.
Ongoing Investigation and Customer Notification
CenterPoint is working with third-party specialists to ascertain the full extent of the breach. This includes identifying affected customers and detailing the specific information compromised. The company plans to notify those impacted, adhering to applicable data breach notification laws, and has reported the incident to law enforcement and certain regulators.
Importantly, CenterPoint has stated that their core electric and gas delivery operations remain unaffected by this cybersecurity incident. This indicates that the breach targeted customer-facing systems, not those involved in operational technology or critical infrastructure.
Potential Impact and Cost Implications
The utility company has not disclosed technical details regarding the compromised system, leaving questions about the method of access open. Typically, such external-facing systems are vulnerable to cyber threats like unpatched software, stolen credentials, or configuration errors.
CenterPoint has incurred costs related to incident response and anticipates additional expenses as the investigation proceeds. These may include forensic analysis, legal consultations, regulatory compliance, and customer communications. The company maintains cybersecurity insurance, which is expected to mitigate some of these expenses. At this point, CenterPoint does not foresee a material impact on its financial condition or operating results due to the breach.
However, the complete ramifications remain uncertain as the investigation continues. The final outcomes will depend on the disclosed scope of the breach, necessary remedial actions, regulatory requirements, and potential insurance recoveries.
