CenterPoint Energy Confirms Data Breach Affecting Customers Across Four States
AI-generated from multiple sources. Verify before acting on this reporting.
HOUSTON — CenterPoint Energy confirmed Monday that a cyberattack compromised the personal information of customers in Texas, Indiana, Minnesota and Ohio after an unauthorized third party accessed one of the utility company's external-facing systems.
The Houston-based energy provider disclosed the incident following the public release of customer data by an unnamed threat actor. The breach involved the extraction of personally identifiable information from the company's digital infrastructure. CenterPoint stated that the intruder gained access through a vulnerability in an external system, though specific technical details regarding the method of entry were not immediately released.
The utility serves millions of customers across its service territories in Texas, Indiana, Minnesota and Ohio. While the company has not yet specified the exact number of individuals impacted, it acknowledged that the leaked data includes sensitive personal details. CenterPoint emphasized that there is no evidence to suggest that financial account numbers or credit card information were accessed during the incident. The utility also stated that its operational systems remain secure and that the breach did not affect the reliability of electricity or natural gas service.
Security experts note that external-facing systems are frequent targets for cybercriminals seeking customer data for identity theft or fraud schemes. CenterPoint has engaged cybersecurity specialists to investigate the scope of the intrusion and is cooperating with federal law enforcement agencies. The company notified relevant state regulators and federal authorities as required by law.
In response to the breach, CenterPoint has activated its incident response plan. The utility is offering complimentary credit monitoring and identity theft protection services to affected customers for a period of 12 months. Customers are being advised to monitor their accounts for suspicious activity and to be vigilant against phishing attempts that may reference the data breach.
The company has not identified the specific group or individual responsible for the attack. The threat actor who leaked the data has not claimed responsibility through public channels, nor have they issued demands for ransom. CenterPoint representatives declined to comment on whether a ransom was paid or if negotiations took place.
As the investigation continues, questions remain regarding the full extent of the data exposed and whether additional customer records were accessed prior to detection. CenterPoint indicated that it will provide further updates as more information becomes available. The utility has urged customers to review their statements carefully and report any unauthorized transactions immediately.
The incident marks a significant security challenge for the energy sector, which has faced increasing scrutiny over cybersecurity vulnerabilities in recent years. CenterPoint's disclosure comes amid a broader trend of data breaches affecting major infrastructure providers across the United States.