The utility filed Monday evening under Item 8.01 rather than Item 1.05, said an unauthorized third party took personal information from an external-facing system, and gave no count, no date, no system name, and no data types.
What happened
CenterPoint Energy filed an 8-K on Monday, September 14, 2026, accepted by EDGAR at 5:15 p.m. ET, accession number 0001104659-26-107560. It was filed jointly by three registrants — CenterPoint Energy, Inc., CenterPoint Energy Houston Electric, LLC, and CenterPoint Energy Resources Corp. — and it reports one item: Item 8.01, Other Events. The filing carries no press-release exhibit. Apart from XBRL taxonomy files, the 8-K document is the entire disclosure.
Here is how it opens, in the company’s words: “In September 2026, CenterPoint Energy, Inc. (the ‘Company’) became aware of an online post by a third party claiming to have obtained a data set containing certain of the Company’s customer information. Upon becoming aware of the post, the Company promptly took action and activated its cybersecurity incident response protocols, initiated an investigation with the assistance of third-party cybersecurity experts, and took steps to further protect the Company’s systems.”
The confirmation comes in the third paragraph: “While the investigation remains ongoing, the Company has determined that an unauthorized third party obtained personal information relating to a portion of the Company’s customers through one of the Company’s external facing systems (the ‘Incident’). The Company is continuing to work with third-party experts to determine the scope of customers and personal information affected by the Incident and intends to notify affected customers and regulatory authorities as required by applicable law. The Company reported the matter to law enforcement authorities and has notified certain regulatory authorities of the issue.”
On operations and materiality: “The Company’s delivery of electric and gas services has not been impacted and remains operational and undisrupted. As of the date of this filing, the Company does not believe it is reasonably likely that there will be a material impact on the Company’s financial condition or results of operations.” And on cost: “The Company has incurred, and expects to continue to incur, certain expenses related to the Incident and its response to the Incident. The Company maintains customary cybersecurity insurance coverage and believes this insurance will offset related costs.”
The filing establishes that data was taken and that CenterPoint has confirmed it. It establishes almost nothing else: no number of affected customers, no categories of personal information, no date or date range for the intrusion, no name for the external-facing system, and no identification of the third party whose post started the clock. It says only “In September 2026” for when the company became aware, placing discovery somewhere in the two weeks before the filing.
Why it matters
Start with where this filing sits. Item 1.05 of Form 8-K is the cybersecurity disclosure item created by the Commission’s 2023 rule; a registrant uses it once it has determined an incident is material. Item 8.01, Other Events, is the general-purpose item for something a company has simply decided to disclose. CenterPoint used 8.01 and then stated, in the same filing, that it “does not believe it is reasonably likely that there will be a material impact.” That is not an oversight or a dodge — it is the two halves of the same decision, and the negative materiality sentence is the tell that the company made the determination rather than deferring it.
The practical consequence is that the SEC is now the least relevant regulator here. If the incident is not material, the federal disclosure obligation is essentially satisfied by what was filed Monday. The obligations that remain are state breach-notification laws, which turn on residents affected rather than on financial materiality, and which are the reason the company says it “intends to notify affected customers and regulatory authorities as required by applicable law.” CenterPoint’s own figures put the denominator in perspective: the company says it sells and delivers natural gas to “approximately 7 million homes and businesses in four states: Indiana, Minnesota (including Minneapolis), Ohio and Texas (including greater Houston area),” and that it serves “more than 2.9 million metered customers” with electric infrastructure in greater Houston and southwestern Indiana. “A portion” of that is the phrase in the filing. There is no numerator, and multiplying a vague fraction by a large denominator would produce a number this page is not willing to print.
The more useful detail is the detection path, and it is easy to skim past. CenterPoint did not learn of this from its own telemetry, a partner, or law enforcement. It learned of it from “an online post by a third party claiming to have obtained a data set.” The company’s incident response began after someone advertised the data publicly. The investigation that followed confirmed the substance of that claim — which is the ordering that matters, and the reason this page treats the theft as confirmed while treating everything about volume and content as open. An attacker’s listing is a claim; a registrant’s determination, filed with the Commission, is not.
That ordering is increasingly the common shape of a breach disclosure. The first signal is an extortion post or a forum listing, and the timeline starts from the adversary’s publishing schedule rather than from detection. Monitoring for your own name in the places stolen data gets advertised is no substitute for detection, but a company that learns about its own breach at the same time as the public has already lost the option of a controlled disclosure.
The second paragraph of the filing is doing real work too. “The Company’s delivery of electric and gas services has not been impacted and remains operational and undisrupted” is the sentence a utility has to write, because the question anyone reads a utility breach disclosure asking is whether the grid moved. The answer here is no, and the filing locates the incident in an “external facing system” holding customer information — the customer-facing side of the IT estate, not the operational technology that runs wires and pipes. That distinction is also what lets a utility hold a customer-data breach to be immaterial: the regulated business is unaffected, the costs are response costs, and there is insurance against those.
Plaintiff firms announced investigations within hours of the filing. Those announcements are not evidence of scope; they are evidence that a public company disclosed a customer-data breach, which is enough on its own to start that process. Anyone sizing this incident from law-firm press releases is reading a reaction to the 8-K, not a second source on it.
What to do
If you are a CenterPoint customer in Texas, Indiana, Minnesota, or Ohio, there is nothing actionable yet and no way to determine from public information whether your data is in the set. The company has said it will notify affected customers. The next primary sources with real content will be the state attorney general breach portals, which publish the notification letters with categories of data and affected counts; California’s list, checked at the time of writing, has no CenterPoint entry, with the most recent filing on it reported September 9, 2026. Treat any unsolicited call or email referencing a CenterPoint breach as a pretext until a notification arrives through a channel you initiated.
If you run a similar estate, the two checks this filing suggests are unglamorous. First, inventory which external-facing systems hold customer personal information and confirm each one is in scope for the monitoring you actually read, not just the monitoring you own. Second, make sure someone is responsible for noticing when your organization’s name appears in a data-for-sale post, and that the path from that notice to your incident response process takes hours rather than days — because in this case that post was the starting gun.
If you are a public company weighing a disclosure decision, this filing is a clean example of the Item 8.01 route: disclose the incident, state the materiality determination explicitly, and say plainly what the investigation has not yet determined. It commits to very little, but it does not claim to know what it does not know.
Sourcing note
Checked: CenterPoint Energy’s Form 8-K filed September 14, 2026, accession number 0001104659-26-107560, accepted at 5:15 p.m. ET, located through EDGAR full-text search and read from the filing index and the 8-K document itself. Every quotation above is from that filing. The customer and service-territory figures are quoted from CenterPoint Energy’s own company overview page. The absence of a California attorney general breach entry was checked against that office’s published breach list, whose most recent entry at the time of writing was reported September 9, 2026.
Could not reach: the Maine attorney general’s breach database has been offline on recent checks and was not treated as checked on this run. No attempt was made to locate or read the “online post” the filing describes; this page does not report attacker claims about volume or data types, and no leak-site listing is used as a source here.
Unresolved: the number of affected customers, the categories of personal information taken, the date or date range of the intrusion, the identity or nature of the external-facing system, and the identity of the party that published the data set are all unstated in the filing and unknown here. No attribution is made. The company’s statement that a material impact is not reasonably likely is its own determination as of the filing date and may change as the investigation continues; this page will follow the state attorney general filings, which are where the affected counts usually appear first.