Skip to content
Back to Blog
high severity September 14, 2026 · 3 min read

CenterPoint Energy Cybersecurity Incident Disclosure

If you are a customer of CenterPoint Energy, here’s what’s now in circulation.

CenterPoint Energy disclosed in an SEC 8-K that it became aware of a third-party claim of obtaining customer data via an external-facing system. The actor claimed ~7.5M customer records including names, contact details, billing data, driver's license numbers, and partial SSNs. The utility confirmed unauthorized access occurred but services remain unaffected.

CenterPoint Energy Cybersecurity Incident Disclosure

Your name, address, phone number, driver's license number, partial Social Security number, and billing information are now in the hands of an unauthorized party. CenterPoint Energy has confirmed that roughly 7.5 million customer records were accessed through an external-facing system after a third party claimed to have obtained the data.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

This is not a password breach. No credentials were exposed, so your CenterPoint account itself remains secure. What was taken, however, consists of permanent and semi-permanent identifiers that identity thieves and fraudsters can use for years.

Your Legal Name and Phone Number Cannot Be Changed

Your Legal Name and Phone Number Cannot Be Changed

Unlike a credit card or password, your legal name and phone number are fixed. Once they are paired with your address, date of birth (often easily found elsewhere), and even a partial SSN, attackers can attempt to open new accounts, file fraudulent tax returns, request replacement documents, or impersonate you in dealings with other utilities, insurers, or government agencies. Driver's license numbers add another strong piece of verifiable identity that many financial institutions still accept.

Exposure Pack · one payment
The full list, and what to lock in ten minutes.
  • Every indexed leak tied to your address — all of them, named and dated
  • What this kind of incident typically exposes
  • A ten-minute lock list written for this kind of organisation
One payment. Nothing renews, and no account is created. Emailed to you within a minute.

The partial SSNs and billing information further tighten the picture an attacker can build. Even a few digits of a Social Security number, when combined with name and address, dramatically raise the success rate of synthetic identity fraud and account takeover attempts on other services.

What the CenterPoint Energy Filing Shows About Its Security Posture

What the CenterPoint Energy Filing Shows About Its Security Posture

The SEC 8-K states the company became aware of a third-party claim that customer data had been obtained via an external-facing system. CenterPoint confirmed unauthorized access occurred. This points to a failure in authentication and authorization controls on systems reachable from the internet. The utility had at least one externally accessible application or API that stored or could retrieve sensitive customer PII without sufficient protection against unauthorized extraction.

Utilities and energy providers have shown this pattern repeatedly: large customer databases exposed through insufficiently secured external systems and APIs. The scale here — 7.5 million records — matches the size of CenterPoint's customer base, but the root cause was preventable with proper access controls.

Why Driver's Licenses and Partial SSNs Retain Value Years Later

Unlike passwords, these data points do not expire. A driver's license number can be used to request official copies of records or to strengthen fraudulent identity proofs. Partial SSNs remain useful for bypassing knowledge-based authentication on financial, tax, and benefits systems. Your address and phone number allow attackers to target you with convincing phishing or to intercept mailed documents. Because this information cannot be rotated like a password, the exposure creates a long-term risk that must be managed through monitoring and fraud alerts rather than a one-time fix.

The Uncertainty That Remains

The filing does not identify the exact system or application involved, whether the data was copied and exfiltrated or simply viewed, or the identity and motive of the threat actor. These details matter because they would indicate how quickly the data may appear on criminal markets, but they were not disclosed.

Concrete Steps That Reduce Your Specific Risk

  • Place a freeze on your credit reports at Equifax, Experian, and TransUnion immediately. This stops most new-account fraud even if an attacker has your name, address, partial SSN, and driver's license.
  • Set up fraud alerts with the three major bureaus and add an extended fraud alert if you have already been a victim of identity theft.
  • Monitor your bank, credit card, and utility statements for unfamiliar charges or changes to billing addresses. Billing information was exposed, so watch for attempts to redirect payments.
  • Contact CenterPoint Energy directly to confirm whether your specific records were in the affected group, especially if you have moved since the incident.
  • Be extremely cautious with any unsolicited contact claiming to be from CenterPoint or any company that would already have this data. Verify requests through official channels before responding.

GalaxyWarden provides continuous monitoring across 13.1B+ breach records and 100+ platforms, identity-chain mapping, and remediation by specialists.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample580 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on CenterPoint Energy.

  1. Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
  2. Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Check your exposure
CenterPoint Energy is one listing. Your email is probably in others.
7.5M accounts were exposed here. We can’t confirm any single incident against the sources we search, so we won’t pretend to — what we can show you is your own exposure: every leak and listing tied to your email, in about 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High identifiers that cannot be reissued, alongside documents or accounts that can be misused now
Disclosed September 14, 2026
Last reviewed September 14, 2026
Affected 7.5M
Data exposed namesaddressesphone numbersdriver's licensespartial ssnsbilling information
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Sources: SEC EDGAR 8-K
Share this Post on X Reddit Email