---
title: "CenterPoint Energy confirms hackers stole custo… | Firevault"
description: "CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/centerpoint-energy-confirms-cyberattack-data-theft-2026#webpage",
      "url": "https://fire-vault.com/news/centerpoint-energy-confirms-cyberattack-data-theft-2026",
      "name": "CenterPoint Energy confirms hackers stole custo…",
      "description": "CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/news/centerpoint-energy-cyberattack-2026.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/centerpoint-energy-confirms-cyberattack-data-theft-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/centerpoint-energy-confirms-cyberattack-data-theft-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "CenterPoint Energy confirms hackers stole customer data through an exposed API",
          "item": "https://fire-vault.com/news/centerpoint-energy-confirms-cyberattack-data-theft-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "CenterPoint Energy confirms hackers stole customer data through an exposed API",
      "description": "CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.",
      "url": "https://fire-vault.com/news/centerpoint-energy-confirms-cyberattack-data-theft-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/centerpoint-energy-cyberattack-2026.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/centerpoint-energy-cyberattack-2026.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/news/centerpoint-energy-cyberattack-2026.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/news/centerpoint-energy-cyberattack-2026.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-09-16T16:10:00+00:00",
      "dateModified": "2026-09-18T05:32:02.285666+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/centerpoint-energy-confirms-cyberattack-data-theft-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 665,
      "keywords": "CenterPoint, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "## What happened CenterPoint Energy, one of the largest utility companies in the United States, has confirmed that an unauthorised third party obtained personal information belonging to some of its customers through one of the company's external facing systems. The confirmation came in a filing with the US Securities and Exchange Commission on 14 September, days after a threat actor posted on a da",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What happened at CenterPoint Energy?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "CenterPoint Energy confirmed in an SEC filing that an unauthorised third party obtained personal information relating to a portion of its customers through one of the company's external facing systems. A threat actor had earlier advertised 7.49 million allegedly stolen files on a dark web forum."
          }
        },
        {
          "@type": "Question",
          "name": "What customer data was taken?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "According to the forum post reported by The Register, the data includes customer names and contact details, billing data, move in dates, driving licence information and the last four digits of Social Security numbers. The claimed volume has not been independently verified."
          }
        },
        {
          "@type": "Question",
          "name": "How did the attackers get in?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The threat actor claims the data was taken through a poorly secured API, an application programming interface exposed to the internet. CenterPoint has confirmed only that an external facing system was involved and that its investigation is ongoing."
          }
        },
        {
          "@type": "Question",
          "name": "Were energy supplies disrupted?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. CenterPoint says the attack did not affect its operations, which continue as normal. The impact is confined to customer data, incident response costs and regulatory obligations."
          }
        },
        {
          "@type": "Question",
          "name": "Why is utility customer data valuable to criminals?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Utility records combine identity details, addresses and billing histories that enable identity fraud and highly convincing phishing. Unlike a password, this information cannot be changed once it is exposed, so it retains criminal value for years."
          }
        },
        {
          "@type": "Question",
          "name": "How can organisations reduce the risk from exposed APIs?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Inventory every external facing interface, restrict what data each can reach and monitor them continuously. Records that must be retained but are rarely needed should be held in offline storage on dedicated hardware, physically disconnected when not in use, so no internet facing system can reach them."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

Buy your Vault

Breaking News Updated as information becomes available 

Overview

What happenedThe front door nobody was watchingCritical infrastructure is not j…The question worth askingSourcesMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 16 September 2026 · Breaking 

# CenterPoint Energy confirms hackers stole customer data through an exposed API

CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fcenterpoint-energy-confirms-cyberattack-data-theft-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fcenterpoint-energy-confirms-cyberattack-data-theft-2026&text=CenterPoint%20Energy%20confirms%20hackers%20stole%20customer%20data%20through%20an%20exposed%20API%0A%0ACenterPoint%20Energy%20has%20confirmed%20that%20criminals%20stole%20customer%20data%20through%20one%20of%20its%20external%20facing%20systems%2C%20after%20a%20threat%20actor%20advertised%207.49%20million%20files%20on%20a%20dark%20web%20forum.%20Mark%20Fermor%20on%20what%20an%20unsecured%20API%20says%20about%20the%20way%20critical%20infrastructure%20treats%20connected%20data.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fcenterpoint-energy-confirms-cyberattack-data-theft-2026)[](mailto:?subject=CenterPoint%20Energy%20confirms%20hackers%20stole%20customer%20data%20through%20an%20exposed%20API&body=CenterPoint%20Energy%20has%20confirmed%20that%20criminals%20stole%20customer%20data%20through%20one%20of%20its%20external%20facing%20systems%2C%20after%20a%20threat%20actor%20advertised%207.49%20million%20files%20on%20a%20dark%20web%20forum.%20Mark%20Fermor%20on%20what%20an%20unsecured%20API%20says%20about%20the%20way%20critical%20infrastructure%20treats%20connected%20data.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fcenterpoint-energy-confirms-cyberattack-data-theft-2026)

![Electricity transmission pylons at dusk overlaid with a cyan network grid, one pylon glowing magenta to signal a compromised system](/news/centerpoint-energy-cyberattack-2026.jpg)

Electricity transmission pylons at dusk overlaid with a cyan network grid, one pylon glowing magenta to signal a compromised system

Why it matters

## What this means for organisations holding critical data

CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.

In this analysis

1.  01 [What happened](#section-0)
2.  02 [The front door nobody was watching](#section-1)
3.  03 [Critical infrastructure is not j…](#section-2)
4.  04 [The question worth asking](#section-3)

**On this page**[What happened](#section-0)[The front door nobody was watching](#section-1)[Critical infrastructure is not j…](#section-2)[The question worth asking](#section-3)

## What happened

CenterPoint Energy, one of the largest utility companies in the United States, has confirmed that an unauthorised third party obtained personal information belonging to some of its customers through one of the company's external facing systems.

The confirmation came in a filing with the US Securities and Exchange Commission on 14 September, days after a threat actor posted on a dark web forum claiming to have stolen 7.49 million CenterPoint files through a poorly secured API. According to The Register, the advertised data includes customer names and contact details, billing information, move in dates, driving licence information and the last four digits of Social Security numbers.

CenterPoint delivers electricity and natural gas to homes and businesses, employs roughly 8,800 people and operates around 48.3 billion dollars in assets. The company says its operations were not affected and continue as normal. It has activated its incident response protocols, brought in third party cyber security experts, notified law enforcement and regulators, and says it will inform affected customers as required by law. It has also warned investors that the incident has already incurred expenses, with more expected as the investigation continues.

The scale claimed by the criminals, 7.49 million files, has not been independently verified. But the company has confirmed the essential point: customer data left the building.

## The front door nobody was watching

If the claim of a poorly secured API proves accurate, this will not be a story about an elite hacking crew defeating state of the art defences. It will be a story about a door that was left unlocked.

APIs are the connective tissue of modern business. They let systems talk to each other, and they are everywhere. They are also routinely treated as plumbing rather than as what they actually are: direct routes into your most sensitive data, reachable by anyone on the internet who cares to look.

I have lost count of the organisations that can tell me in detail how their perimeter is defended, but cannot tell me how many external facing interfaces they have, what data each one can reach, or when anyone last checked. The perimeter gets the budget and the attention. The quiet connections get neither.

## Critical infrastructure is not just the grid

When we talk about protecting [critical infrastructure](/control-for-critical-infrastructure), the conversation usually jumps straight to operational technology: the control systems, the substations, the physical network. CenterPoint says its operations were unaffected, and that matters. Nobody's lights went out.

But a utility is more than its grid. It is also decades of customer records: names, addresses, billing histories, [identity documents](/oss-for-identity-documents). For a criminal, that dataset is a gift. It enables identity fraud, highly convincing phishing and targeted social engineering against millions of households, and it never expires. You cannot change your move in history or your billing record the way you change a password.

If your organisation holds data that would harm your customers for years if it were published, the question is not whether it sits behind a firewall. The question is whether it needs to be connected at all.

## The question worth asking

Every external facing system in your estate should be able to answer three questions. What data can it reach? Who is watching it? And does the data behind it need to be there?

Where records must be retained for regulatory or operational reasons, [Offline Secure Storage](/offline-secure-storage)® keeps them on dedicated hardware that is physically disconnected when not in use. An exposed API cannot leak an archive it cannot reach, and a criminal forum cannot advertise what was never connected in the first place.

Audit every connection as if it were a door, because that is exactly what it is. And put your crown jewels somewhere the doors do not go.

_Mark Fermor is the founder of Firevault._

## Sources

-   [TechRadar Pro: CenterPoint Energy confirms hackers compromised networks and stole data](https://www.techradar.com/pro/security/centerpoint-energy-confirms-hackers-compromised-networks-and-stole-data-and-the-hackers-claim-theft-of-7-5-million-files)
-   [CenterPoint Energy 8-K filing with the US Securities and Exchange Commission, 14 September 2026](https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=0001130310&type=8-K)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters](/news/us-coast-guard-tanker-cyberattacks-2026.jpg)

Breach Analysis 

### FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

17 Sept 2026 4 min 







](/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026)[

![FBI investigates 153 million drivers licenses put up for sale on a criminal forum](/news/fbi-drivers-licenses-dark-web-2026.jpg)

Breach Analysis 

### FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

16 Sept 2026 4 min 







](/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026)[

![Southampton council reported seven serious data breaches in a year, including a lost notebook with 224 residents' details](/news/southampton-council-data-breaches-2026.jpg)

Breach Analysis 

### Southampton council reported seven serious data breaches in a year, including a lost notebook with 224 residents' details

Southampton City Council referred seven incidents to the Information Commissioner's Office in 2025/26, including a social worker's lost notebook containing the names, addresses and key safe numbers of 224 people. Mark Fermor on what a notebook, a miscatalogued archive and a curious officer tell us about the data organisations still cannot control.

16 Sept 2026 5 min 







](/news/southampton-council-seven-serious-data-breaches-2026)[

![Southport court files breach: the access was authorised, the purpose was not](/__l5e/assets-v1/8c5ecf7a-e4db-4dcb-b6dd-3585f89078ee/southport-court-files-insider-access-2026.jpg)

Breach Analysis 

### Southport court files breach: the access was authorised, the purpose was not

The Ministry of Justice has confirmed that courts staff accessed files relating to victims, survivors and families of the Southport attack without authorisation. It is the third insider access case connected to the attack, and it shows why perimeter security alone cannot protect the most sensitive records.

16 Sept 2026 5 min 







](/news/southport-court-files-insider-access-breach-2026)[

![Military flight plan reportedly triggered the NATS outage, unless you ask the MoD](/news/nats-outage-military-flight-plan-2026.jpg)

Breach Analysis 

### Military flight plan reportedly triggered the NATS outage, unless you ask the MoD

Flight data filed for a UK military aircraft reportedly set off the 8 September NATS failure, according to the Financial Times. The Ministry of Defence says there was no error on its part. Mark Fermor on what a single filing emptying the national schedule says about resilience.

12 Sept 2026 5 min 







](/news/nats-outage-military-flight-plan-resilience-2026)[

![Trezor breach reaches 81,000 customers because a supplier never deleted the data](/images/news/trezor-shipmonk-data-breach-81000-customers-2026.jpg)

Breach Analysis 

### Trezor breach reaches 81,000 customers because a supplier never deleted the data

A further 67,000 US customers who ordered between 2019 and 2021 were exposed, because Trezor's logistics provider kept data it had confirmed in writing it had deleted.

8 Sept 2026 3 min 







](/news/trezor-shipmonk-data-breach-81000-customers-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)