Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts
Description
Southern Company has disclosed a data breach affecting approximately 400,000 customer accounts across its electric utilities Georgia Power, Alabama Power, and Mississippi Power. An unauthorized third party accessed limited customer account information via the company's online customer portal. The compromised data includes names, mailing addresses, phone numbers, emails, last four digits of Social Security numbers, and other basic account details. Sensitive financial information such as bank account numbers, payment card numbers, and driver’s license numbers were not accessed. The company has notified affected customers and is offering one year of free credit monitoring. The breach was detected and stopped promptly, with law enforcement engaged. Details about the intrusion timeline and attack vector have not been disclosed.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Southern Company reported that hackers accessed limited customer account information for roughly 400,000 accounts through its online customer portal. The affected accounts include approximately 300,000 Georgia Power customers and 100,000 Alabama Power customers; Mississippi Power was also affected but no specific number was provided. The data accessed includes customer names, mailing addresses, phone numbers, email addresses, last four digits of Social Security numbers, and other basic account details. The breach did not expose bank account numbers, payment card numbers, or driver’s license numbers. The company took immediate action to stop the unauthorized access and has involved law enforcement. Impacted customers are being notified and offered credit monitoring services. The exact method and timing of the breach have not been disclosed.
Potential Impact
The breach exposed personally identifiable information (PII) of approximately 400,000 utility customers, including names, contact information, and partial Social Security numbers. While financial account details and driver’s license numbers were not accessed, the exposed data could facilitate identity theft or targeted phishing attacks. The breach affects customer privacy and may erode trust in Southern Company's data security practices. The company’s prompt response and credit monitoring offer mitigate some potential harm.
Defensive Guidance
Southern Company has already taken immediate steps to stop the unauthorized access and engaged law enforcement. Affected customers have been notified and offered one year of free credit monitoring. No additional mitigation actions are specified or recommended at this time. Customers should remain vigilant for phishing attempts or suspicious communications.
Technical Details
- Classification
- {"confidence":0.95,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/georgia-power-alabama-power-data-breach-hits-400000-accounts/","fetched":true,"fetchedAt":"2026-10-07T14:18:24.027Z","wordCount":989}
Threat ID: 6ac654b22cdf04f656560f0f
Added to database: 10/07/2026, 14:18:26 UTC
Last enriched: 10/07/2026, 14:18:32 UTC
Last updated: 10/07/2026, 16:48:40 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.