CenterPoint Energy filed a Form 8-K on 14 September 2026 confirming that an unauthorised third party had obtained personal information relating to a portion of its customers through one of its external-facing systems. The company said it became aware of the incident in September through a post on a cybercrime forum, would notify customers and regulators as required, and expected insurance to offset response costs. Electricity and gas service were not affected.
The forum post, on 12 September, offered about 7.49 million records in JSON and CSV: names, phone numbers, email and service addresses, account and premise identifiers, billing amounts, autopay and paperless status and the last four digits of Social Security numbers. CenterPoint serves about 7 million accounts across Texas, Indiana, Minnesota and Ohio. The seller claimed the source was a public API with no web application firewall, no rate limiting and no authentication token, and said the company had ignored their messages.
Two Documents, One Event
The seller’s listing has a count, a field list and a mechanism. The company’s filing has none of the three. Both are about the same theft, and the corpus applies the same rule to each at 26-0425: the seller’s figures are claims until verified, and the company’s silence is not a denial. What the filing does confirm, an external-facing system and a portion of customers, is consistent with the seller’s account and rules nothing out. Class actions were filed in three states before the 8-K was.
What A Utility Record Enables
A utility account is not a financial record, and the four digits of a Social Security number are the ones most other institutions use to confirm identity over the phone. Combined with a service address and billing history, the record is enough to impersonate the customer to the utility and to most call centres that ask for the last four. The inference argument at 26-0306 applies: no single field is sensitive, and the join is.
Learning From The Seller
CenterPoint discovered its breach the way an increasing share of organisations in this database do: by reading about it. The corpus filed the same order of events at 26-0825, where a tax authority’s confirmation followed a forum listing, and at 26-0827, where an agency confirmed an incident after a leak-site entry. If the seller’s account of an unauthenticated API is right, the theft would have been invisible in logs that recorded only ordinary requests, which is the mechanism’s point.
Compiled from CenterPoint’s Form 8-K as quoted by press and contemporaneous reporting of the forum listing, listed below. The 7.49 million count, the field list and the API mechanism are the seller’s claims and are labelled as such; the company has confirmed only the theft. Graded medium. Corrections: corrections@forensicpost.com.