TEXAS utility CenterPoint Energy has confirmed that an unauthorised third party obtained personal information belonging to some customers through one of its external-facing systems. The Houston-based company, which supplies electricity and natural gas to about 7 million customers in Indiana, Minnesota, Ohio and Texas, disclosed the incident to the US Securities and Exchange Commission on Monday and said it has launched an investigation.
The disclosure followed a 12 September post on a cybercrime forum in which a hacker claimed to have stolen nearly 7.5 million customer records and released a 2.5GB archive allegedly taken from CenterPoint. SecurityWeek said it could not verify the archive’s contents, noting that criminal actors sometimes make false or exaggerated claims.
The hacker also threatened future attacks against the utility’s “main infrastructure”, but there is no reported evidence that operational systems were targeted or that services were disrupted.
CenterPoint said the incident has not affected electricity or gas delivery and that it does not believe the breach will have a material impact. The company has not yet publicly detailed the types of personal information involved or confirmed how many customers were affected.
The report also notes previous claims involving CenterPoint data, including incidents linked by analysts to the Cl0p ransomware group’s 2023 MOVEit campaign; those records were believed to have originated from a third party rather than directly from CenterPoint’s systems.