ThreatPaper
Unverified

The CenterPoint breach exposed partial Social Security numbers

Assessment

The claim that the stolen data included the last four digits of Social Security numbers, alongside names, contact details, account identifiers and billing information, is drawn from the threat actor's own description of the dataset, as relayed by CyberInsider and Security Affairs. CenterPoint's 8-K does not enumerate the affected data fields at all, stating only that 'personal information' was obtained and that the investigation is still determining what was accessed. Because SSN exposure drives regulatory notification obligations and consumer harm, treating this attacker-sourced detail as confirmed overstates what CenterPoint has actually acknowledged.

Where this claim appeared

CyberInsider (reporting the threat actor's claim) · 2026-09-15

https://cyberinsider.com/centerpoint-energy-confirms-data-breach-after-hacker-claims-7-49m-records/

What “Unverified” means

Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.

2 of 5 · rating scale

Assessed in

CenterPoint Energy breach: a confirmed intrusion, and a 7.49M-record claim only the attacker is making

Think this assessment is wrong? Report an error.