CenterPoint Energy has confirmed a customer data breach in which an unauthorized third party obtained personal information relating to a portion of its customers through an external-facing system. The company’s September 14 SEC filing confirms the compromise, but it does not establish in the reviewed disclosure exactly how many customers were affected or provide the complete list of personal-information fields involved.
That distinction matters because several larger figures and detailed data-field claims circulating in third-party reporting originated from threat-actor claims, litigation or other non-controlling sources. Those claims should not be treated as proof that a specific CenterPoint customer was affected.
What CenterPoint has confirmed
CenterPoint said it became aware in September of an online post claiming possession of customer information and activated its incident-response process. With outside cybersecurity experts, the company investigated and determined that an unauthorized third party had obtained personal information relating to some customers through an external-facing system.
The company also said its electric and gas delivery operations remained operational and undisrupted. This is therefore a customer-information security incident, not a confirmed outage or operational disruption to utility delivery.
What remains unknown about the CenterPoint Energy data breach
The reviewed SEC filing does not give a confirmed affected-customer count. It also does not provide the complete set of exposed personal-information fields or identify the exact technical method used to access the external-facing system.
Reports citing an alleged dataset of roughly 7.5 million records or files should not be converted into a statement that 7.5 million CenterPoint customers were confirmed affected. Likewise, reported references to Social Security information, driver’s-license data, billing details or a guest-payment or API weakness remain outside the facts CenterPoint confirmed in the filing reviewed by TPS.
How customers can verify whether they are affected
CenterPoint said it intends to notify affected customers as required. A personalized notice is stronger evidence of individual exposure than a general media report or alleged leak count.
If you receive a breach-related email, text or call, independently confirm it through a CenterPoint account, known company contact method or another trusted official channel before following links or providing information.
Do not assume specific identifiers were exposed until CenterPoint or another controlling official notice identifies the relevant data fields for your record.
If a later notice confirms sensitive identity or financial information was involved, follow the protections in that notice and current official guidance rather than relying on unverified breach claims.
Has CenterPoint said how many customers were affected?
No confirmed affected-customer count was provided in the reviewed September 14 filing. CenterPoint said it was continuing to determine which customers and which personal information were involved.
This means the currently responsible answer to an individual customer’s question is not that everyone in a reported dataset is necessarily affected. Public confirmation of a company-level incident and confirmation of an individual’s exposure are different evidence states.
What personal information was exposed?
CenterPoint confirmed that personal information was obtained, but the complete field set was not specified in the reviewed filing. TPS therefore does not treat detailed field lists from threat-actor claims or lawsuits as company-confirmed facts.
If CenterPoint later publishes customer notices, state breach filings or another regulatory disclosure containing a field-by-field description, that information should update this same canonical article.
Are customer notifications already complete?
The reviewed filing says CenterPoint intends to notify affected customers and regulators as required by law. It does not establish that all affected customers have already been identified or that the notification process has been completed.
Customers who have not received a notice should therefore avoid assuming either that they were affected or that they were definitely excluded while the investigation remains incomplete.
What happens next
The most important next evidence is likely to come from CenterPoint customer notifications, state breach filings, another SEC disclosure or investigation updates that identify the affected population and exact personal-information fields. Any confirmed identity-protection or credit-monitoring offer should also be added when officially disclosed.
The same URL should be updated as those facts become available. A separate article is justified only if a materially different reader job emerges, such as a confirmed identity-theft recovery process or a distinct authoritative technical root-cause finding.