VYPR
breachPublished Oct 7, 2026· 1 source

Georgia Power, Alabama Power Data Breach Exposes 400,000 Customer Accounts

Southern Company disclosed a data breach affecting Georgia Power and Alabama Power customers, with hackers accessing utility account information for approximately 400,000 accounts.

Southern Company, the parent energy holding company for Georgia Power, Alabama Power, and Mississippi Power, has revealed that an unauthorized third party gained access to the utility account information of approximately 400,000 customers through its online portal. The breach specifically impacted around 300,000 Georgia Power accounts and an estimated 100,000 Alabama Power accounts, with Mississippi Power also named as affected, though specific numbers for that subsidiary have not yet been released.

According to the company's public notice, the accessed data was limited and included customer names, mailing addresses, phone numbers, email addresses, and in some cases, the last four digits of Social Security Numbers, along with other basic account details. Crucially, Southern Company stated that the attackers did not obtain access to sensitive financial information such as bank account numbers or payment card details, nor did they access driver's license numbers.

The full extent of the intrusion, including the exact timeline and the method used by the attacker to compromise the customer portal, has not yet been disclosed by Southern Company. Upon detecting the unauthorized activity, the company reported taking immediate steps to halt the access and has since engaged with law enforcement agencies to investigate the incident.

Customers whose accounts were affected are being notified directly via mail and email. As a measure to help mitigate potential harm, Southern Company is offering a complimentary year of credit monitoring services to all impacted individuals. This proactive step aims to provide a layer of protection against identity theft or fraud.

This incident highlights the persistent threat to critical infrastructure and utility providers, which hold vast amounts of customer data. The compromise of even limited personal information can still pose significant risks to individuals, underscoring the importance of robust security measures for customer-facing portals and data protection protocols.

While the company has not detailed the specific vulnerabilities exploited, such breaches often stem from weaknesses in web application security, credential stuffing attacks, or sophisticated phishing campaigns targeting employees with privileged access. The ongoing investigation will likely shed more light on the attack vector and inform future security enhancements.

The disclosure adds to a growing list of data breaches affecting large organizations, emphasizing the need for continuous vigilance and investment in cybersecurity defenses across all sectors. The energy sector, in particular, faces unique challenges due to its critical role in society and the potential for widespread disruption.

Southern Company's response, including customer notification and credit monitoring, follows standard industry practices for data breach incidents. However, the incident serves as a stark reminder for all consumers to remain vigilant about their personal information and to monitor their accounts for any suspicious activity.

Synthesized by Vypr AI