The incident is still being investigated, and the most important details for customers remain unknown. CenterPoint has not disclosed the number of affected customers or individuals, the categories of data obtained, the specific system involved, the access method, the dates of unauthorized activity, or whether operational technology was reached. Those omissions are not proof that the situation is either smaller or broader than currently known; they define the limits of what can responsibly be concluded.
What CenterPoint has confirmed
CenterPoint says it became aware in September of an online post asserting that a third party had obtained a dataset containing some customer information. The company activated its incident-response procedures, engaged outside cybersecurity experts, and took additional steps to protect its systems.
Its subsequent assessment confirmed that an unauthorized party acquired personal information concerning a portion of customers through one of its external-facing systems. CenterPoint also says it has reported the matter to law enforcement and notified certain regulators. It is working with third-party experts to identify affected customers and the information involved, with legally required notifications planned once that work supports them.
The company disclosed that it has incurred, and expects to continue incurring, response costs. It expects customary cybersecurity insurance to offset related expenses. As of September 14, it said it did not believe the incident was reasonably likely to materially affect its financial condition or results of operations. That is an assessment at a particular point in an ongoing investigation, not a final accounting of costs, regulatory exposure, or potential claims.
For customers, the operational point is straightforward: CenterPoint has stated that its electric and gas delivery services were not affected and remained undisrupted. A compromise of a customer-facing or internet-exposed environment can be serious without meaning that generation, delivery, dispatch, or industrial controls have been compromised. The company has not published enough technical detail to establish the separation of every system involved, but neither has it reported an interruption of utility service.
The 7.49 million claim is an allegation, not a confirmed impact count
Online discussion has focused on a reported claim of more than 7.49 million records. That number should not be treated as CenterPoint’s confirmed count of affected people, customers, files, or accounts.
The available report describing the alleged leak explicitly says that authenticity, the number of distinct individuals, the data fields, and the access method were not independently verified. CenterPoint itself has not disclosed a record total, an affected-customer total, or an affected-person total.
There is an additional reason to be careful with large figures. CenterPoint reported serving more than 7 million metered customers across Indiana, Minnesota, Ohio, and Texas as of June 30, 2026. That is a company-wide service statistic, not a breach count. It cannot establish that every customer was affected, nor can it validate a claimed number of leaked records. A single person can appear in multiple records, and a dataset may contain outdated, duplicate, incomplete, or non-customer entries. Conversely, an unannounced customer count does not prove that the impact is trivial.
The right conclusion for now is narrower: CenterPoint has verified unauthorized acquisition of personal information associated with some customers, while the scale remains undetermined in public disclosures.
No confirmed API failure or confirmed data categories
Another popular framing is that a poorly secured application programming interface, or API, caused the incident. The evidence currently available does not support that conclusion. CenterPoint refers to an “external-facing system,” but it does not identify that system as an API, describe an authorization flaw, identify a request-rate problem, or provide a root cause.
An external-facing system can cover a wide range of technologies: a customer portal, web application, vendor-connected service, remote administration interface, or another internet-reachable component. Until CenterPoint or investigators release technical findings, assigning a specific entry point would turn an unverified claim into apparent fact.
Likewise, reported assertions about specific exposed information—including names, contact details, billing information, service or move-in information, driver’s-license details, and the last four digits of Social Security numbers—have not been independently verified or confirmed by CenterPoint. The company has confirmed only “personal information.” Customers should take sensible precautions without assuming any one particularly sensitive data category was definitely involved.
That distinction is more than semantic. The appropriate response can differ sharply depending on what was acquired. An email address and service address may raise the risk of targeted phishing. Government-issued identification information can create a different kind of identity-fraud concern. Account credentials, if affected, would require a different immediate response still. Until affected people receive direct information describing the relevant data, broad but measured account-security hygiene is more useful than speculation.
What customers should do now
Customers do not need to wait for every investigative detail before reducing common risks. The goal is not to react as though every account has been taken over; it is to make fraud attempts less likely to succeed.
Start with the email account attached to any utility relationship. Email is often the recovery channel for online accounts, so it deserves the strongest unique password available and multi-factor authentication where supported. If that password has been reused on a CenterPoint-related account or elsewhere, replace it with a new, unique password. A password manager can make unique credentials practical across banking, utility, retail, and government accounts.
Be especially cautious with messages claiming to be from the utility, a regulator, law enforcement, a credit-monitoring provider, or a payment processor. A criminal who has basic customer information may be able to make an email or text look credible. Do not use unexpected links or phone numbers delivered in a message to resolve an alleged billing problem, refund, outage, enrollment request, or security alert. Instead, open a known official app or manually enter a known address, or use contact information from a bill you already possess.
Windows users should also treat this as a reminder to keep their PC and browser current. Install security updates, use the browser’s anti-phishing protections, and avoid downloading “breach verification” tools or documents sent by unsolicited email. Legitimate notification does not require a customer to install an unknown program, grant remote access to a PC, or disclose a one-time authentication code.
Review utility-account contact details and payment settings by signing in through an established route. Watch for unrecognized changes to email addresses, phone numbers, bank details, autopay settings, or mailing addresses. Customers should also monitor financial statements and credit reports using the processes available to them. If CenterPoint sends a notification, read the stated facts closely: affected information, relevant dates, remediation steps, and any offered support can be assessed more reliably than rumors circulating online.
At this stage, people should avoid sharing screenshots of customer correspondence, account pages, or purported leaked data in public forums. Doing so can amplify fraud risk for the person posting it and for anyone whose information is visible.
Why service continuity does not make the incident insignificant
It would be a mistake to dismiss the event simply because service delivery continued. Utility customer data can support phishing, social engineering, identity-fraud attempts, and scams timed around bills, moves, service transfers, storms, or outages. Attackers do not need to shut off power or gas to impose real costs on customers and an organization.
But the reverse error also matters. A data incident at a utility does not by itself demonstrate compromise of industrial control systems or an imminent threat to the grid. CenterPoint’s disclosure supports a confirmed customer-information incident and continued electric and gas operations. It does not identify an attack on operational technology, describe manipulation of physical processes, or establish a wider grid threat.
The distinction is important in the current critical-infrastructure environment. Federal agencies have warned that internet-connected operational-technology devices across critical-infrastructure sectors are being exploited and that state-linked actors continue to target energy organizations. Separate government reporting says cyberattacks in 2026 targeted more than 100 drinking-water and wastewater systems across 12 states; reported activity at utilities in at least seven states included some operational degradation, such as loss of pressure and flooding.
Those are meaningful warnings about exposure at the infrastructure edge, particularly where internet-facing control equipment is involved. They are not evidence that the CenterPoint incident was caused by the same actors, used the same techniques, or reached the same kinds of systems.
International examples also show why precision is essential. In Poland, a December 2025 attack at a combined heat-and-power plant shut down a steam turbine and water-treatment system, causing a short-term outage, though consumer heat supplies were not disrupted. Reporting on a small U.K. power facility described a four-day July 2026 shutdown following a suspected Iran-linked attack, without a threat to the wider grid. These events demonstrate that cyber incidents can have physical consequences, while also showing that the scale and downstream service effects of individual attacks vary greatly.
What to watch for next
The next meaningful update will not necessarily be a larger headline number. The most useful information would be a clear account of who is affected, what information was involved, when access occurred, whether data was copied or merely accessed, and what actions customers should take. Technical findings on the affected external-facing system and the remediation performed would also help customers and security professionals judge the event’s significance.
Other unresolved questions include the intruder’s identity, whether the alleged dataset is authentic and connected to the confirmed incident, the scope of regulatory notifications, and whether CenterPoint will offer identity-protection or other support. Financial and legal effects also remain unsettled despite the company’s current assessment that the incident is not reasonably likely to be material to its financial condition or operating results.
For now, the evidence supports neither panic nor complacency. CenterPoint has confirmed a real unauthorized acquisition of customer-related personal information and says utility operations continued without disruption. The public does not yet have verified answers on the count, data types, technical cause, or broader consequences. Customers should secure accounts, verify communications independently, and rely on direct notifications and confirmed disclosures as the investigation develops.