CenterPoint customer data exposed through an internet-facing system
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Thursday, September 17th, 2026.
CenterPoint Energy has confirmed that an unauthorized third party obtained personal information belonging to some customers. The utility said the data was accessed through an internet-facing company system after it learned of an online post claiming to offer customer information. CenterPoint hasn’t disclosed how many people were affected or which categories of personal data were involved. Its electric and gas delivery operations remain unaffected while the investigation continues.
The immediate concern is customer privacy rather than service disruption. Once the exposed data types are confirmed, affected people may face targeted phishing or account abuse. The company also expects additional costs for investigation, notification and remediation, although it doesn’t currently expect a material effect on its financial condition or operating results.
Leaders should keep customer trust and regulatory obligations separate from the status of operational technology. Defenders should review public-facing systems, authentication controls and data-access patterns while preserving evidence. The larger lesson is that critical infrastructure organizations can suffer serious privacy harm even when physical services continue normally. Identify affected customers quickly, harden internet-facing systems and prepare targeted guidance based on the confirmed data types.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.