A woman in Houston gets an email on a Friday evening from “CenterPoint Energy Billing.” It has her account number, her service address, the amount of her last bill and the words disconnection scheduled for Monday. There is a button to pay now. Everything in it matches her real account, because everything in it may have come from her real account. That is what the CenterPoint Energy breach hands to whoever bought the file, and the file is already on a cybercrime forum.
Confirmation: the incident is confirmed by the company, in a filing with the SEC on 14 September 2026. The 7.49 million figure and the list of what was taken are the attacker’s claims, reported by BleepingComputer and others, and not yet confirmed by CenterPoint.
What happened
On 14 September 2026, CenterPoint Energy told the SEC that “an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external facing systems.” That is the whole of what the company has confirmed, in an 8-K filing that says it became aware in September of a post claiming to hold customer data, activated its incident response, brought in outside cybersecurity experts, reported the matter to law enforcement and some regulators, and “intends to notify affected customers and regulatory authorities as required by applicable law.”
The post came first. Around 12 September, according to SecurityWeek, someone using the alias 4d722e4d656f77 put a 2.5 GB archive up for download on a cybercrime forum and said it held roughly 7.49 million CenterPoint customer records. The same person told BleepingComputer the data was pulled between 17 August and 1 September through a public-facing CenterPoint API with no rate limiting and no web application firewall in front of it. CenterPoint has not confirmed the count, the dates, the method or the contents of the file. Its words are “a portion of the Company’s customers,” and it says it is “continuing to work with third-party experts to determine the scope.”
CenterPoint delivers electricity and gas to households in Texas, Indiana, Minnesota and Ohio, with Houston as its largest territory. The company says the lights and the gas were not affected and it does not expect the breach to hurt its finances. Class actions on behalf of customers were filed in federal court within a day, per BleepingComputer.
What was exposed
According to the attacker’s post, the file holds names, phone numbers, email addresses, service and billing addresses, account and premise identifiers, billing amounts, payment information, autopay and paperless-billing status, and the last four digits of Social Security numbers (CyberInsider has the list; BleepingComputer and The Record report the same core fields). Treat it as a claim until CenterPoint’s notice letters say otherwise. If it is accurate, here is what each item is worth to the person holding it:
- Name, account number and service address. Enough to pass as CenterPoint to you. Enough, with a little more, to pass as you to CenterPoint.
- Email address and phone number. The two delivery routes for the fake bill. If email is in the file, the “disconnection notice” arrives in your inbox with your real account number in the subject line.
- Billing amounts and payment information. The detail that makes the fake bill match the real one. A scam that quotes your own August charge to the cent is very hard to spot.
- Autopay and paperless-billing status. The scammer knows whether you expect bills by email at all, and whether “your autopay failed” is a story you will believe.
- Last four of the SSN. Not enough on its own. Exactly enough to answer the verification question on a phone call, and exactly what a caller will offer you as proof that they are the real utility.
No passwords are listed. Nothing here opens a CenterPoint login by itself. What it opens is you.
What to do now
Most of this is about your bills and your phone, not about OptMsg, and none of it takes long.
1. Do not pay a utility bill from a link in an email or a text. Go to the CenterPoint site by typing the address, or use the app you already have, or call the number printed on a paper bill. A real disconnection comes with written notice and time to respond, not a same-day button. 2. Treat any call about your CenterPoint account as unverified until you started it. The last four of an SSN and your account number are what the caller will use to sound real. Hang up and call back on the printed number. 3. Check your CenterPoint account for changes you did not make: contact email, mailing address, autopay bank details. A changed contact email is how a takeover survives your noticing. 4. Turn on the strongest sign-in your email account offers. Your email is where the bill lands and where the account resets. A passkey where available, an authenticator app otherwise. 5. Watch for the notice letter. CenterPoint says it will notify affected customers as the law requires. The letter is where you will learn whether your email address and partial SSN were in the file, and whether monitoring is on offer. If it offers credit or identity monitoring, take it. 6. Search your address at Have I Been Pwned once the dataset is loaded there. That is the fastest way to know if you are in the 7.49 million.
How OptMsg changes this exposure
Honestly, and at its real size: OptMsg would not have prevented this. The data came out of a CenterPoint system, and no choice you make about your inbox changes what a utility keeps on its servers. What an opt-in inbox changes is what the file is worth against you afterwards.
The attack that follows a breach like this one is not a login attack. It is a message: the fake bill, the fake disconnection, the fake refund, sent to the address in the file from a domain that looks like CenterPoint. Mail from a sender you have not approved goes to Trash, not your Inbox, and auto-deletes after 30 days. OptMsg’s patent-pending opt-in technology means the message from centerpoint-billing-notice.com lands in Trash, not in front of you on a Friday evening with your account number in it. The real CenterPoint reaches your Inbox once you have approved it. Only people you approve can reach your inbox. Everyone else goes to Trash. And if a message in Trash comes from a sender many other OptMsg users have opted in to, you get a push alert, so a real notice is not lost.
There is a second, smaller point. If a password had been in that file, it would have been tried against email accounts next, because the inbox is what resets everything else. Your OptMsg account has no password, so a password stolen from another site can’t open your inbox. No password was listed here, but the next file will have one.
What that does not cover: the phone call, which is the route that the last-four-of-the-SSN detail is built for; a text message; a phishing page you open yourself; a message from a sender you did approve whose own account was taken; a compromised device; or someone with your unlocked phone. Those are the six steps above, and the first two are the whole defence against the call and the text.
If you want an inbox where the fake bill cannot get in front of you, see how Simple by Design works, or read why your inbox should not care about a leaked password.
Ready for an inbox that only holds the mail you asked for? Create Your Account.
Your Inbox. Your Rules.
Frequently asked questions
What happened in the CenterPoint Energy data breach? CenterPoint Energy told the SEC on 14 September 2026 that an unauthorized third party obtained personal information about a portion of its customers through one of its external-facing systems. A hacker had posted a 2.5 GB file on a cybercrime forum days earlier claiming about 7.49 million customer records.
How many CenterPoint customers were affected? CenterPoint has not said. The attacker claims 7.49 million records. The company says it is still working out the scope and will notify affected customers as required by law.
What information was exposed in the CenterPoint breach? According to the attacker’s post: names, phone numbers, email addresses, service and billing addresses, account and premise identifiers, billing amounts, payment information, autopay and paperless status, and the last four digits of Social Security numbers. CenterPoint has not confirmed the list.
Was my CenterPoint password stolen? No passwords are listed in the reported data, and CenterPoint has not said any were taken. The risk is a convincing fake bill or call, not a stolen login. Check your account for changes you did not make anyway.
Would OptMsg have stopped the CenterPoint breach? No. It happened inside CenterPoint’s systems. What OptMsg changes is the aftermath: mail from a sender you have not approved goes to Trash rather than your Inbox, so the fake disconnection notice built from this data has a shorter path.
Sources
- CenterPoint Energy, Inc. Form 8-K, Item 8.01 — 14 September 2026
- BleepingComputer: CenterPoint Energy confirms customer data stolen in cyberattack — 15 September 2026
- SecurityWeek: Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data — 15 September 2026
- The Record: Electric and gas utility CenterPoint Energy warns of data breach after dark web post — 15 September 2026
- CyberInsider: CenterPoint Energy confirms data breach after hacker claims 7.49M records — 15 September 2026