Houston-based utility CenterPoint Energy has told regulators that an unauthorized third party obtained personal information relating to some customers through an external-facing system. The company opened an investigation after becoming aware of a claim that customer data had been obtained.
In its filing with the U.S. Securities and Exchange Commission, CenterPoint said the incident had not affected delivery of electric or natural-gas services and that it did not expect a material effect on the company. The filing did not validate a hacker’s separate claim about the number of records involved.
SecurityWeek reported that a threat actor had advertised an archive allegedly containing CenterPoint data. That claim remains unverified, so the confirmed facts are narrower: customer information was accessed, an investigation is underway, and operational utility delivery continued.
Why it matters
The separation between customer-facing systems and operational service delivery is important for critical infrastructure. A breach can create serious privacy and fraud exposure even when operational technology remains available, and incident reporting should keep those impacts distinct.
For wider context, see SectechMedia’s related technical coverage.
