CenterPoint confirms customer data theft from an external-facing system
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Wednesday, September 16th, 2026.
CenterPoint Energy has confirmed that an unauthorized party stole personal information relating to some customers through an external-facing system. An attacker claimed to have taken 7.49 million records, but CenterPoint hasn’t confirmed that number or the specific types of data involved. The company says its electric and natural gas services weren’t disrupted, and the investigation is still active.
The immediate consequence is a growing customer-trust and legal problem, even though physical services continued normally. Affected customers may face targeted scams once the exposed fields and full scope are known. Leaders should separate confirmed facts from attacker claims and explain clearly when customers will receive notice. Defenders should examine external systems for weak access controls and test public APIs against automated collection. Proposed class-action lawsuits have already been filed, showing how quickly a data incident can create wider business consequences. CenterPoint’s priority should be to complete the scope assessment, strengthen external systems, and provide affected customers with specific guidance based on the data that was actually exposed.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.