CenterPoint Energy Data Breach Exposes Social Security Numbers and Account Information

Published: 15 September 2026
Energy data breach illustration
Breach Discovery: September 2026Breach Notification: September 2026

CenterPoint Energy confirmed hackers stole customer personal information, reportedly including names, phone numbers, addresses, account numbers, billing amounts, and partial Social Security numbers, after exploiting an unprotected public API. The breach affects an unknown portion of the company’s roughly 7 million customers across Indiana, Minnesota, Ohio, and Texas. Affected individuals should monitor credit reports and consider a fraud alert or credit freeze immediately.

CompanyCenterPoint Energy
IndustryEnergy
Data Types ExposedFull Names, Phone Numbers, Service Addresses, Billing Addresses, Account Numbers, Billing Amounts, Partial Social Security Numbers
People AffectedNot Publicly Disclosed
Attack MethodUnauthorized API Access
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the CenterPoint Energy Data Breach?

CenterPoint Energy has confirmed a data breach after a hacker claimed to have stolen millions of customer records from the utility company. The company discovered the incident after finding an online post from an attacker claiming responsibility. This discovery led CenterPoint Energy to launch a formal investigation into what actually happened.

According to reports, a threat actor using an online alias said they pulled 7.49 million customer records from the company’s systems. The attacker reportedly exploited a public-facing application programming interface, or API, that lacked basic protections like rate limiting and a web application firewall. As a result, the intruder could reportedly cycle through customer ID numbers automatically to pull data at scale.

The breach reportedly occurred sometime in September 2026, though CenterPoint Energy has not confirmed the exact timeline publicly. In response, the company brought in outside cybersecurity experts to determine the full scope of the incident. CenterPoint Energy also filed a disclosure with the U.S. Securities and Exchange Commission, confirming that an unauthorized third party accessed personal information tied to a portion of its customer base.

Importantly, the company has stated that its core electric and gas services were not disrupted by the attack. CenterPoint Energy also said it does not currently expect the breach to have a material effect on its business or finances. However, the investigation into the CenterPoint Energy data breach remains ongoing, and further details may still emerge.

Who was affected?

The individuals affected by this incident are customers of CenterPoint Energy, a utility provider serving electric and natural gas customers across several states. The company reports serving roughly 7 million metered customers across Indiana, Minnesota, Ohio, and Texas. Because utility service is often mandatory for households, this breach could touch a very broad cross-section of residents in those states.

CenterPoint Energy has not publicly disclosed the exact number of customers affected by this specific breach. Therefore, the precise scope remains unknown at this time. The company has stated it is still working with forensic experts to determine exactly who was impacted and what data was involved.

Given the nature of utility billing systems, both residential and business account holders could potentially be affected. It’s also possible that former customers with historical account records were included in the exposed data. CenterPoint Energy has said it intends to notify affected individuals as required by law once the investigation concludes.

What Information Was Potentially Exposed?

While CenterPoint Energy’s official regulatory filing does not list specific data categories, the attacker who claimed responsibility described the types of information taken. This claimed data set includes several categories of sensitive personal and account information.

  • Full names
  • Phone numbers
  • Service addresses
  • Billing addresses
  • Account numbers
  • Billing amounts
  • Partial Social Security numbers

This combination of data is concerning because it blends identity information with financial account details. For example, a partial Social Security number combined with a full name and address can still be useful to a fraudster attempting identity theft. In addition, account numbers and billing details could potentially be used to impersonate customers when contacting the utility or other service providers.

Because utility accounts are often used to verify identity for other services, this exposure carries added risk. Scammers frequently use stolen account and billing information to craft convincing phishing messages that appear to come from a legitimate utility provider. As a result, affected customers should be alert to fraudulent communications that reference real account details in an attempt to appear legitimate.

What is the company doing?

CenterPoint Energy has activated its incident-response procedures following discovery of the breach. The company has also hired third-party cybersecurity experts to investigate the scope and cause of the incident. In addition, CenterPoint Energy has taken steps to strengthen protections on the affected systems to prevent further unauthorized access.

Furthermore, the company reported the incident to law enforcement and regulatory authorities. CenterPoint Energy filed a formal disclosure with the U.S. Securities and Exchange Commission, confirming the theft of customer data through an external-facing system. The company has said it intends to notify affected customers and regulators as required by applicable law once its investigation determines the full scope of the incident.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected individuals should regularly check their credit reports for signs of unauthorized activity. Because partial Social Security numbers were reportedly involved, monitoring is an important precaution. You can request free credit reports from each of the three major credit bureaus at AnnualCreditReport.com.

Look closely for new accounts, unfamiliar inquiries, or changes to your personal information on file. If you notice anything suspicious, report it to the credit bureau immediately. Consistent monitoring over the coming months is especially important, since stolen data is sometimes used long after a breach occurs.

Consider a Fraud Alert or Credit Freeze

Given that partial Social Security numbers and account information were reportedly exposed, placing a fraud alert on your credit file is a reasonable step. A fraud alert requires lenders to take extra steps to verify your identity before opening new credit. This can help prevent identity thieves from opening accounts in your name.

For stronger protection, you might also consider a credit freeze. This blocks most new creditors from accessing your credit report entirely. While it takes a few extra steps to lift a freeze when you need credit, it offers one of the most effective defenses against new-account fraud.

Watch for Phishing Attempts

Because names, addresses, and account numbers were reportedly leaked, scammers may use this information to craft realistic phishing emails, texts, or phone calls. These messages might impersonate CenterPoint Energy itself, asking you to verify account details or make a payment. Always be skeptical of unsolicited requests for personal or payment information.

Instead of clicking links in unexpected messages, contact CenterPoint Energy directly using a phone number from your bill or its official website. This helps confirm whether a communication is legitimate. Additionally, never share your Social Security number or banking details in response to an unverified request.

Review Your Utility and Financial Accounts

Take time to review your CenterPoint Energy account statements for any unusual charges or account changes. Because billing amounts and account numbers were reportedly part of the exposed data, this account deserves particular attention. Report any irregularities to the company right away.

Similarly, review your bank and credit card statements for unfamiliar transactions. Given the scale of the reported records involved, it’s wise to stay vigilant across all your financial accounts, not just your utility account. If you spot anything wrong, contact your financial institution immediately to dispute the charges.

Know Your Legal Options

Multiple lawsuits have already been filed against CenterPoint Energy related to this incident. If you were affected, you may have options to pursue compensation for damages related to the breach. Consulting with a data breach attorney can help you understand your rights and whether you qualify to join a class action.

Many attorneys offer free case evaluations for individuals affected by data breaches like this one. This means you can learn about your options without any upfront cost or obligation. Given the ongoing litigation already underway, acting sooner rather than later may help preserve your ability to participate in any settlement.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

See the latest data breaches we're tracking →