Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 16, 2026 · 7 min read

CenterPoint Energy Breach: Hacker Claims 7.5M Records

CenterPoint Energy told the SEC on September 15, 2026 that an unauthorized party took customer personal information through an external facing system. A dark web seller claims the haul is 7.49 million records. The utility has confirmed neither the number nor the dataset, which is exactly the gap phishing crews like to work in.

Power kept flowing. Gas kept flowing. What moved was a database, and the part of it that matters is not dramatic at all: your name, your account number, your service address, a billing amount, and the last four digits of your Social Security number. That is not the stuff of a ransomware headline. It is the stuff of a very good fake bill.

Key Takeaways

  • CenterPoint Energy disclosed in an SEC filing dated September 15, 2026 that an unauthorized third party obtained customer personal information through an external facing system, while electric and gas service ran uninterrupted.
  • A threat actor using the alias 4d722e4d656f77 posted on September 1, 2026 claiming roughly 7.49 million raw records and 6.73 million filtered records, a figure CenterPoint has not confirmed. Source: The Record
  • The categories CenterPoint itself points to include customer names, account information, billing information, and the last four digits of Social Security numbers.
  • The seller claims the data came from a company API that lacked adequate authentication and rate limiting, a claim CenterPoint has not addressed.
  • Americans reported losing $3.5 billion to imposter scams in 2025, with business impersonation alone accounting for nearly $1 billion. Source: FTC

What Did CenterPoint Actually Confirm?

CenterPoint confirmed that an unauthorized third party obtained personal information belonging to some of its customers through an external facing system, and that its electric and gas operations were not affected. That is the whole of the confirmed story.

The company says it activated its incident response protocols, brought in outside cybersecurity experts, reported the matter to law enforcement, and expects no material financial impact. Its own language on scope is deliberately open: the company "is continuing to work with third-party experts to determine the scope of customers and personal information affected by the Incident and intends to notify affected customers and regulatory authorities as required by applicable law," per the filing reported by The Record.

No threat actor has been named. No attribution, no compromise window, no confirmed record count. If you are a customer, you have not been told whether you are in the dataset, and that uncertainty is what scammers will sell you a solution to.

Where Does the 7.5 Million Figure Come From?

The 7.5 million number comes from the seller, not the utility. An actor using the alias 4d722e4d656f77 posted on an open forum on September 1, 2026 advertising about 7.49 million raw records and 6.73 million after deduplication, according to CyberInsider.

Treat it as a claim, but note the arithmetic. CenterPoint serves roughly 7 million customers across Indiana, Minnesota, Ohio and Texas, so 7.49 million records is not a slice of the customer book. It is a number consistent with all of it, plus closed accounts and duplicates. Sellers inflate. Sellers also sometimes do not have to.

The claimed field list runs wider than CenterPoint's summary: names, phone numbers, email addresses, service and billing addresses, account and premise identifiers, billing amounts, payment status, autopay and paperless billing status, and partial Social Security numbers. Email address plus autopay status plus billing amount is, functionally, a targeting file. It tells a sender who to write to, what to claim, and how much to claim.

Overhead power transmission lines against an overcast sky above a suburban street, with a residential electricity meter on a house wall in the foreground

Why Is Utility Billing Data Such a Good Phishing Kit?

Utility billing data is a phishing kit because it supplies every detail a victim uses to decide an email is real, before the victim even reads the ask. Generic phishing fails on specificity. This data removes that failure mode.

A generic lure says "your account is past due, click here." A lure built from this dataset says: account 4471-0932, service at 1408 Maple Ridge Drive, balance $214.86, autopay declined, disconnection scheduled Thursday. Every one of those details checks out, because every one came from the real billing system. The reader stops evaluating the sender and starts worrying about the bill.

This is the same economics we covered when Microsoft tracked over a million AI generated invoice scam emails aimed at US firms. Generative tools made the prose cheap. Breaches like this one make the facts cheap. When both inputs cost nothing, volume stops being a constraint and the only remaining defense is the reader. Utility lures also carry a deadline the reader believes in, which is why the FTC counted imposter scams as nearly one in three fraud reports in 2025.

Why the Last Four of Your SSN Proves Nothing

A message that quotes the last four digits of your Social Security number is not proving it came from your utility; it is proving whoever wrote it has a copy of a database. After this incident, those four digits are best read as a warning sign rather than a credential.

Partial identifiers were always weak, and volume finished them off. Driver's license and identity records now move in bulk, as we saw when the Nexus marketplace advertised 153 million driver's licenses. A verifier that millions of strangers can already recite is not a verifier.

There is a second reason to distrust it: no legitimate utility needs to show you your own SSN digits in an email. Real billing notices identify you by account number and service address. Quoting SSN fragments is a persuasion move, and persuasion moves belong to the attacker. The FTC's guidance on recognizing phishing makes the same point in general terms: urgency plus a payment link is the pattern, regardless of how much the sender appears to know.

What This Means for Your Inbox

If you are a CenterPoint customer, assume for the next several months that any utility email you receive could have been written by someone holding your real account details. Not because it probably was, but because the cost of assuming otherwise is a payment sent to a stranger.

The practical rule is out of band verification, and it is boring on purpose. Never click a payment link in a utility email. Open a new browser tab, type the utility's address yourself, sign in, and look at the balance the account actually shows. If there is no past due amount there, the email is fake, no matter how many correct facts it recited. Phone numbers in the email are part of the email, so use the number printed on a paper bill or on the back of your card instead.

Watch the money movement, because that is where these scams give themselves away. Real utilities do not demand same day payment by prepaid card, wire, crypto, or a QR code scanned at a convenience store counter, and real disconnections arrive after weeks of written notice. The same "pay now or lose the service" shape ran through the fake cloud storage payment emails flooding inboxes earlier this year. Only the brand changes.

What to Watch Next

Two things will tell you how bad this is. The first is CenterPoint's notification letters, which will finally put a confirmed number and a confirmed field list against the seller's claim. The second is whether anyone corroborates the API story, because the actor's claim that an unauthenticated, unthrottled API served the data would make this an architecture failure rather than an intrusion.

That distinction matters beyond one utility. An exposed customer lookup endpoint is not a CenterPoint invention. It is a common shape across regulated industries that bolted self service portals onto decades old billing systems. If the claim holds, the question is not who took CenterPoint's data. It is how many other utilities run the same endpoint and have not yet met someone willing to enumerate it.

The breach is already monetized whether or not the sale completes. The records exist, the customer list is plausible, and the lure writes itself. Treat the next past due notice in your inbox as unverified until your own browser tab says otherwise.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.