CenterPoint Energy has confirmed that an unauthorized third party obtained personal information belonging to some of its customers through an external-facing system, days after a threat actor claimed to have obtained millions of records associated with the U.S. utility company.
The Houston-based energy provider disclosed the incident in a Sept. 14 filing with the U.S. Securities and Exchange Commission. CenterPoint said it became aware earlier in September of an online post from a third party claiming to possess a dataset containing customer information.
CenterPoint activated its cybersecurity incident response procedures, launched an investigation with third-party cybersecurity experts and implemented additional measures to protect its systems.
The investigation has since confirmed that an unauthorized third party obtained personal information relating to a portion of CenterPoint customers. The company has not yet disclosed how many people were affected or exactly what categories of personal information were compromised.
Threat actor claims 7.49 million records
Before CenterPoint publicly confirmed the breach, a threat actor claimed to have obtained and released approximately 7.49 million records associated with the company’s customers.
The actor alleged that the dataset contained customer contact information, utility account and billing details, service addresses, driver’s license information and the last 4 digits of Social Security numbers, among other information.
The threat actor also made claims about how the information was obtained from CenterPoint’s systems. BreachNews is not reproducing those technical details because CenterPoint has not independently confirmed the claimed intrusion method.
CenterPoint’s SEC filing does not validate the claimed 7.49 million-record figure or confirm that all of the data categories described by the threat actor were exposed.
A record count would also not necessarily represent the number of unique individuals affected, since datasets can contain multiple records associated with the same customer or account.
What CenterPoint has now confirmed is that an unauthorized party obtained personal information belonging to some customers through one of its externally facing systems.
Scope of exposed customer information still under investigation
CenterPoint said it is continuing to work with outside cybersecurity experts to determine both the number of customers affected and the specific personal information involved.
The company intends to notify affected customers and regulatory authorities where required by law.
CenterPoint has also reported the incident to law enforcement and notified certain regulators.
The uncertainty surrounding the scope means the eventual number of affected customers could differ significantly from the 7.49 million records claimed by the threat actor. The company’s investigation will also be important in determining whether the information circulating online is authentic and how closely it corresponds with the data CenterPoint confirmed was accessed.
Electricity and natural gas services were not disrupted
Despite the compromise of customer information, CenterPoint said the incident did not affect its delivery of electricity or natural gas.
The company’s services remain operational and undisrupted, an important distinction given CenterPoint’s role as a major U.S. energy provider.
CenterPoint provides electric transmission and distribution, natural gas distribution and other energy services across multiple states. A cyberattack affecting operational technology or systems responsible for delivering electricity and natural gas could carry significantly different consequences from the customer data breach currently under investigation.
There is currently no evidence disclosed by CenterPoint indicating that the attacker gained access to systems responsible for controlling electricity or natural gas infrastructure.
The company also said it does not currently believe the incident is reasonably likely to have a material impact on its financial condition or operating results.
CenterPoint expects breach-related costs
CenterPoint has already incurred expenses associated with investigating and responding to the incident and expects additional costs as its response continues.
The company said it maintains cybersecurity insurance coverage that it believes will offset costs associated with the breach.
The incident has also prompted proposed class-action litigation. Lawsuits filed before CenterPoint’s confirmation alleged that millions of customer records were compromised and accused the company of failing to adequately protect personal information. Those allegations have not been adjudicated, and the number of affected customers remains under investigation.
CenterPoint’s confirmation significantly changes the status of the incident from an unsupported online leak claim to a verified compromise involving customer personal information. However, major questions remain about its scale, the precise data exposed and how the unauthorized party accessed the external-facing system.
CenterPoint said its investigation remains ongoing and that affected customers will be notified as required by applicable law.











