CenterPoint Energy, a Houston-based electric and gas utility, filed an 8-K form with the Securities and Exchange Commission confirming it became aware this month of a dark web post claiming to offer data stolen from the company. An investigation into those claims found that hackers did obtain personal information relating to a portion of the company's customers through one of its external-facing systems.

The company said delivery of electric and gas services has not been impacted. It also said it is continuing to work with third-party experts to determine the scope of customers and personal information affected, and intends to notify affected customers and regulatory authorities as required by applicable law. CenterPoint said it reported the incident to law enforcement in addition to the regulatory filing.

The cybercriminal post itself claims roughly 7.5 million records were taken, including customer names, account information, the last four digits of Social Security numbers and billing information. A CenterPoint spokesperson declined to answer other questions about that post. The company's filing does not confirm those figures, and the source does not treat them as established. CenterPoint said it will incur some costs related to the investigation but that the incident is not likely to have a material impact on its finances.

For readers trying to judge their own exposure, the useful detail is the entry point: the company attributes the access to an external-facing system rather than to its service delivery. CenterPoint provides power and natural gas to 7 million customers across Indiana, Minnesota, Ohio and Texas, so the pool of potentially affected people is large even if the confirmed scope is described only as a portion of customers. The source does not say which customers, how they will be told, or what they should do in the meantime. That gap matters: the protective step a reader can act on is not yet specified in the evidence available.

This is also not the company's first such disclosure. Last year CenterPoint announced it was investigating another data breach tied to a 2023 incident in which hackers stole customer information through a popular file sharing platform. The source does not connect the two incidents, and no such link should be assumed.