Back to Feed
BreachesOct 7, 2026

Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts

Southern Company utility breach exposes 400K customer accounts including names, addresses, and SSN last 4 digits.

Summary

Southern Company notified approximately 400,000 customers that an unauthorized third party accessed their utility account information through the company's online customer portal. The breach affected roughly 300,000 Georgia Power accounts and 100,000 Alabama Power accounts, with exposed data including customer names, mailing addresses, phone numbers, emails, and last 4 digits of Social Security Numbers. The company reports that attackers did not access bank account numbers, payment card numbers, or driver's license numbers, and affected customers are being offered one year of free credit monitoring.

Full text

Southern Company is notifying roughly 400,000 customers that their utility account information was accessed by an unauthorized third party through its online customer portal. The Atlanta-based energy holding company serves more than 9 million customers through electric utilities in three states and natural gas distribution businesses in four. Its electric subsidiaries are Georgia Power, Alabama Power and Mississippi Power. Roughly 300,000 of the affected accounts belong to Georgia Power customers. According to Southern Company, the incident also impacted roughly 100,000 of Alabama Power’s 1.6 million accounts. Mississippi Power is named as affected in the company’s public notice, but no figure has been released for its customers. “An unauthorized third party accessed certain, limited information about the accounts of approximately 400K customers. Upon detection, we took immediate steps to stop the activity and have engaged law enforcement,” the company said in a statement sent to the media. Southern Company’s public notice specifies the type of data involved. “Based on our investigation to date, the limited customer account information that the unauthorized party gained access to includes the customer’s name, mailing address, phone number, email, or the last 4 digits of their Social Security Number, and other basic account details,” the notice reads.Advertisement. Scroll to continue reading. The utility says the attacker did not access bank account numbers, payment card numbers or driver’s license numbers. Southern Company has not said when the intrusion took place or how the attacker gained access to the portal. Impacted customers are being notified by mail and email and offered a year of free credit monitoring. Related: ASOS Confirms Cyberattack, Data Breach Related: Advantest Discloses Data Breach Months After Ransomware Attack Related: 8.8 Million Impacted by Data Breach at Denmark’s Central Person Register Related: Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs FBI Blames Contractor’s Missed Patch for ShinyHunters BreachCybersecurity M&A Roundup: 39 Deals Announced in September 2026Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated ReportsExploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days EarlierCrypto Scammers Hijack Microsoft’s Official X AccountAI Agents Aimed SQL Injection at US and Canadian Government SitesPolice Shut Down KillSec Ransomware, Identify Alleged Teen LeaderTreasury Blacklists Most-Wanted ATM Malware Developer and His Network Latest News Qilin Ransomware Suspect Arrested in Japan, Extradited to GermanyHadrian Raises $40 Million to Expand Autonomous Offensive Security PlatformAdvantest Discloses Data Breach Months After Ransomware AttackChrome 155 Update Patches 247 VulnerabilitiesAnthropic Introduces 3-Tier Cyber Verification Program for AI AccessASOS Confirms Cyberattack, Data BreachWikimedia Says Rogue OpenAI Agents Tried to Turn Its Tools Into ProxiesAndroid’s October 2026 Updates Patch 25 Vulnerabilities Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveChip Wentz has been appointed as SVP & CISO at Keurig Dr Pepper Inc.Lumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email

Entities

Southern Company (vendor)Southern Company Online Customer Portal (product)Georgia Power (vendor)Alabama Power (vendor)Mississippi Power (vendor)