What happened and when: the essential timeline
On September 14, 2026, CenterPoint Energy filed a Form 8-K. In the filing, the company reported that an unauthorized third party had obtained personal information belonging to some of its customers through an external system. It also said that it had activated response measures, was investigating the scope of the incident, and had not experienced an impact on the delivery of electricity and gas services. (SEC Form 8-K filing)
In the days around the filing, TechRadar reported on a threat actor’s public claim about files allegedly taken. That coverage provides context about what the actor claimed, but it does not independently verify either the volume or the contents of the data. (TechRadar)
What CenterPoint’s 8-K confirms—and what it does not
The filing confirms that an unauthorized third party obtained personal information belonging to some customers through an external system. CenterPoint said it was determining which customers and what data might have been affected, that it would notify customers and authorities as appropriate, and that it had notified law enforcement. It also said that it had cybersecurity insurance and did not, at that time, expect incident-related expenses to be material. (SEC Form 8-K filing)
The document does not give a final count of affected people, identify the specific categories of information compromised, or list the states affected. The company added that, as of the filing date, it did not expect a material impact on its financial condition or results, subject to the ongoing investigation. The absence of a published count does not, by itself, allow anyone to infer how many people are involved or what data was obtained. (SEC Form 8-K filing)
The figures being circulated: separate claims from evidence
TechRadar reported the threat actor’s claim that up to 7.5 million files had been taken. That figure is attributed to the actor; it is not a count confirmed by CenterPoint in its SEC filing. Also, files and affected people are not interchangeable measures: a collection may include duplicate records or multiple files relating to one person. (TechRadar)
Without an official, itemized count, the publicly confirmed information is more limited: the 8-K acknowledges that a third party obtained customers’ personal information and says the investigation is ongoing. These sources do not support presenting millions of files as the number of affected customers. The scope and categories of data will have to be established through the investigation and any required notifications. (SEC Form 8-K filing)
Operations and data: what it means that service continued
CenterPoint said that electricity and gas delivery had not been affected and that its operations were continuing. This is a statement about service continuity: on its own, it does not establish which specific systems were accessed or prove that the intrusion was confined to customer-facing IT systems. The 8-K does not publicly identify affected systems at that level of detail. (SEC Form 8-K filing)
It is important to keep two issues separate: continuity of supply and exposure of personal information. The company said the first was unaffected but acknowledged that customer data had been obtained. As a general precaution, be wary of unexpected messages asking for information, payments, or account access, and verify any contact through official channels. This advice does not establish that any particular message is connected to the incident.
The regulatory framework: the SEC and Texas notifications
The SEC rule on cybersecurity risk management, strategy, governance, and incident disclosure took effect on September 5, 2023. Among other requirements, it provides for disclosure on Form 8-K of incidents a company considers material, as well as periodic information about risk management and governance. CenterPoint’s filing is a specific corporate disclosure; it should not be interpreted as proof that every detail of the incident has already been determined. (SEC rule)
In Texas, the Office of the Attorney General says organizations must report a breach affecting 250 or more state residents within 30 days of discovering it and notify affected consumers. Whether these requirements apply depends on the circumstances and the confirmed scope; the threshold does not allow anyone to infer how many Texas residents are affected in this case. (Texas Attorney General: breach reporting)
What customers should do today (and what to avoid)
Watch for official communications from CenterPoint, but be cautious with unexpected links or attachments asking for personal information, login credentials, or payments. To check a notice, sign in to your usual portal by typing its address yourself, or use a phone number obtained from an official source—not one supplied in an unsolicited message. Do not assume that every message related to the incident is authentic, even if it uses the company’s name.
If a notification confirms that your data was involved, follow the specific instructions it provides. Depending on the information available and your circumstances, you may consider a fraud alert or a credit freeze; the FTC explains these options and how they differ. These are general protective measures, not confirmation that customers’ financial data was compromised in this incident. (FTC: credit freezes and fraud alerts)
At a glance: what remains to be clarified
The 8-K does not provide a final count of affected customers or detail the types of information obtained or the states involved. These details are needed to assess the extent of exposure, but their absence does not support concluding that the number of files claimed by the actor equals the number of people affected. The filing says the investigation is continuing. (SEC Form 8-K filing)
The technical origin of the access and whether identity-monitoring services will be offered to customers also remain unclear. The available sources do not resolve those questions. Until more details are published, figures attributed to the actor should remain distinct from facts stated by the company; customers can follow official communications and take general precautions.