The CenterPoint breach exposed partial Social Security numbers
Assessment
The claim that the stolen data included the last four digits of Social Security numbers, alongside names, contact details, account identifiers and billing information, is drawn from the threat actor's own description of the dataset, as relayed by CyberInsider and Security Affairs. CenterPoint's 8-K does not enumerate the affected data fields at all, stating only that 'personal information' was obtained and that the investigation is still determining what was accessed. Because SSN exposure drives regulatory notification obligations and consumer harm, treating this attacker-sourced detail as confirmed overstates what CenterPoint has actually acknowledged.
Where this claim appeared
CyberInsider (reporting the threat actor's claim) · 2026-09-15
https://cyberinsider.com/centerpoint-energy-confirms-data-breach-after-hacker-claims-7-49m-records/What “Unverified” means
Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.
2 of 5 · rating scale
Assessed in
CenterPoint Energy breach: a confirmed intrusion, and a 7.49M-record claim only the attacker is makingThink this assessment is wrong? Report an error.