Breaches · 4h ago

CenterPoint Breach Exposes Fraud-Ready Customer Data

CenterPoint Energy said an unauthorized third party obtained personal information on some customers through one of its external-facing systems, after a dark web post claimed about 7.5 million records from the utility. The company said electric and gas service was not affected and that it has notified regulators and law enforcement.

The data described in the post includes names, account information, billing details, and the last four digits of Social Security numbers. That mix matters because it is enough to support account takeover attempts, identity checks built on weak verification, and follow-on fraud aimed at customers, not just a privacy complaint.

For utilities that keep billing data and partial SSNs behind customer-facing systems, the exposure sits at a trust boundary that can outlive the incident itself. Even if the breach turns out to be narrower than the post claims, the customer records already known to be exposed still carry a fraud and impersonation blast radius.

Timeline

Sources

3 sources covering this story

Part of the PlainSec briefing for 2026-09-15

Editions

Related stories