Georgia Power, Alabama Power customer portal breach hits about 400,000 accounts
Southern Company says an unauthorized party accessed limited account information of roughly 400,000 utility customers through its online customer portal.
At a glance
- An unauthorized third party accessed customer data through Southern Company's online customer portal.
- About 300,000 Georgia Power and 100,000 Alabama Power customers are affected; Mississippi Power is also named without a figure.
- Exposed data includes names, addresses, phone numbers, emails and the last four digits of Social Security numbers.
- The company says bank, payment card and driver's license numbers were not accessed and offers one year of credit monitoring.
Atlanta-based energy holding company Southern Company is notifying roughly 400,000 customers of its utility subsidiaries that an unauthorized third party accessed their account information through the company's online customer portal, SecurityWeek reported on October 7. Southern Company serves more than 9 million customers through electric utilities in three states and natural gas distribution businesses in four.
What happened
In a public notice cited by SecurityWeek, the company described the incident as access to "certain, limited information about the accounts of approximately 400K customers." Southern Company said it took immediate steps to stop the activity after detecting it and has engaged law enforcement.
The company has not said when the intrusion began, when it was discovered, how the attacker gained access to the portal, or who was responsible. No group had publicly claimed the attack at the time of SecurityWeek's report.
Who is affected
According to the publication, about 300,000 of the affected customers are Georgia Power account holders and roughly 100,000 are among Alabama Power's 1.6 million accounts. Mississippi Power, the group's third electric utility, is named in the notice, but no number has been released for its customers.
The data exposed includes customer names, mailing addresses, phone numbers, email addresses, the last four digits of Social Security numbers and other basic account details. Southern Company said bank account numbers, payment card numbers and driver's license numbers were not accessed.
What to do
Affected customers are being notified by mail and email and are being offered one year of free credit monitoring, the company said. Because the stolen combination of contact details and partial Social Security numbers can be used to make phishing calls, texts and emails look convincing, customers should be wary of messages that appear to come from Georgia Power, Alabama Power or Mississippi Power and ask for payment, login details or additional personal information. Customers should reach the utility only through official channels, enroll in the offered credit monitoring and consider a credit freeze if they notice suspicious activity.
Organizations running customer self-service portals can treat the incident as a reminder to monitor for credential stuffing and unusual bulk account access, enforce multi-factor authentication for customer accounts where possible and limit the amount of personal data displayed in portal sessions.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



