CENTERPOINT ENERGY INC disclosed a cybersecurity incident
What the company disclosed
In September 2026, CenterPoint Energy, Inc. (the "Company") became aware of an online post by a third party claiming to have obtained a data set containing certain of the Company's customer information. Upon becoming aware of the post, the Company promptly took action and activated its cybersecurity incident response protocols, initiated an investigation with the assistance of third-party cybersecurity experts, and took steps to further protect the Company's systems.
The Company's delivery of electric and gas services has not been impacted and remains operational and undisrupted. As of the date of this filing, the Company does not believe it is reasonably likely that there will be a material impact on the Company's financial condition or results of operations.
While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company's customers through one of the Company's external facing systems (the "Incident"). The Company is continuing to work with third-party experts to determine the scope of customers and personal information affected by the Incident and intends to notify affected customers and regulatory authorities as required by applicable law. The Company reported the matter to law enforcement authorities and has notified certain regulatory authorities of the issue.
The Company has incurred, and expects to continue to incur, certain expenses related to the Incident and its response to the Incident. The Company maintains customary cybersecurity insurance coverage and believes this insurance will offset related costs.
Forward-Looking Statements
This Current Report on Form 8-K (the "Current Report") may contain "forward-looking statements" within the meaning of Section 27A of the Securities Act and Section 21E of the Exchange Act. All statements other than statements of historical fact included in this Current Report are forward-looking statements made in good faith by us and are intended to qualify for the safe harbor from liability established by the Private Securities Litigation Reform Act of 1995. When used in this Current Report, the words "continue," "may," "potential," "will" or other similar words are intended to identify forward-looking statements. These forward-looking statements are based upon assumptions of management which are believed to be reasonable at the time made and are subject to significant risks and uncertainties. Actual events and results may differ materially from those expressed or implied by these forward-looking statements. The Company assumes no obligation and does not intend to update or revise these forward-looking statements, whether as a result of new information, future events or otherwise, except as required by securities and other applicable laws. Forward-looking statements include, but are not limited to, our expectations regarding any impact on the Company's financial condition or results of operations, the timing and nature of expenses in connection with the Incident, availability of insurance and potential impact on customers and the Company. Each forward-looking statement contained in this Current Report speaks only as of the date of this report. Important factors that could cause actual results to differ materially from those indicated by the provided forward-looking information include risks and uncertainties relating to (1) the timing and nature of any remediation expenses incurred in connection with the Incident, (2) the availability of cybersecurity insurance proceeds, (3) the extent of regulatory compliance obligations, (4) the risk that the scope of the Incident is greater than initially expected and (5) other factors discussed in the Company's Annual Report on Form 10-K for the fiscal year ended December 31, 2025, the Company's Quarterly Reports on Form 10-Q for the quarters ended March 31, 2026 and June 30, 2026 and other reports the Company may file from time to time with the Securities and Exchange Commission.
Quoted from the company’s own Form 8-K, Item 1.05, as filed with the US Securities and Exchange Commission. SEC filings are works of the US federal government and are in the public domain.
The record
- Organisation
- CENTERPOINT ENERGY INC (CNP) →
- Identity
- CENTERPOINT ENERGY INCidentified by its SEC Central Index Key (0001130310)
- Records affected
- Records not disclosed
- Sector
- Electric ServicesSIC 4911, from the company’s own filing
- Occurred
- Not disclosed
- Disclosed
- 2026-09-14
- First recorded here
- 2026-09-16
Sources (1)
One source so far.
- SEC EDGAR ↗First reported
2026-09-14