LIVE · cybersecurity feed
Live wire
breach

Electric and gas utility CenterPoint Energy warns of data breach after dark web post

Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web.

zeroday.news ·

Photo: Wikimedia Commons (Public domain) via Wikimedia Commons

CenterPoint Energy, a major electric and gas utility, has confirmed a data breach after discovering a dark web post claiming to offer stolen customer data. The Houston-based company filed an 8-K form with the Securities Exchange Commission (SEC) on Monday evening, September 14, 2026, acknowledging that an investigation into the claims revealed unauthorized access to one of its external-facing systems.

The company stated that personal information belonging to a portion of its customers was obtained by hackers. CenterPoint Energy is currently working with third-party experts to determine the full scope of affected customers and the specific types of personal information compromised. It intends to notify impacted customers and relevant regulatory authorities as required by law.

While CenterPoint Energy confirmed the data theft, it declined to comment on specific claims made in the dark web post. The post reportedly alleges that approximately 7.5 million records were stolen, containing details such as customer names, account information, the last four digits of Social Security numbers, and billing information.

CenterPoint Energy emphasized that the incident has not impacted the delivery of electric and gas services to its 7 million customers across Indiana, Minnesota, Ohio, and Texas. The company has reported the incident to law enforcement.

The utility anticipates incurring some costs related to the investigation and remediation efforts, but it does not expect the incident to have a material impact on its financial performance. CenterPoint Energy reported a net income of $244 million in the second quarter of 2026.

This is not the first data breach for CenterPoint Energy. In 2025, the company announced an investigation into a separate 2023 incident where customer information was stolen through a popular file-sharing platform.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s