CenterPoint Energy, the primary electric and gas utility for Spring households, confirmed Monday, Sept. 14, that an unauthorized third party stole personal information belonging to some of its customers.

The company disclosed the breach in a Form 8-K filing with the U.S. Securities and Exchange Commission on Sept. 14. CenterPoint said it learned earlier in September about an online post claiming a third party had obtained a dataset of customer information. The company activated its cybersecurity response protocols and brought in outside experts to investigate.

That investigation confirmed the breach. But CenterPoint has not said how many customers were affected, what types of personal information were taken, or when the intrusion occurred.

A CenterPoint spokesperson told KPRC 2, "Our filing speaks for itself."

Five lawsuits already filed

The SEC disclosure came days after customers began suing. Five proposed class-action lawsuits had been filed in federal court as of Monday, Sept. 14, according to KHOU 11. Three were brought by Florida law firm Shamis and Gentile on behalf of customers Laurie Eirwin, Latoya Wyche and Christa Floyd. Two more were filed by Dallas law firm Lippe and Associates on behalf of Joyce Curry and Nathaniel Sonia. The named plaintiffs are residents of Indiana, Texas and Minnesota.

The lawsuits allege the breach occurred between Aug. 17 and Sept. 1 and that cybercriminals accessed names, phone numbers, addresses, billing information and Social Security numbers, according to the Houston Chronicle. Three of the suits point to CenterPoint's guest bill pay feature as the alleged point of entry.

No class has been certified in any of the cases.

What Spring residents should know

CenterPoint serves roughly 2.9 million electric customers across Greater Houston, including Spring. The company has not confirmed how many local accounts were compromised.

CenterPoint said it reported the incident to law enforcement and notified certain regulatory agencies. Electric and gas services were not disrupted, the company said.

Under the Texas Identity Theft Enforcement and Protection Act (ITEPA), businesses must notify affected Texas residents no later than 60 days after determining a breach occurred. If 250 or more Texans are affected, the company must also notify the Texas Attorney General within 30 days. As of Sept. 8, no state attorney general filings related to the incident had been made public, according to a report from teiss.co.uk.

CenterPoint said it maintains cybersecurity insurance and expects that coverage to offset related costs.

Next steps for Spring customers

CenterPoint said it intends to notify affected customers as required by law but has not announced a timeline. The Texas Attorney General's office accepts identity theft complaints online.