SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Southern Company's online portal exposed account data on about 400,000 utility customers
Southern Company is notifying about 400,000 customers that an intruder accessed their account details, including partial SSNs, through its online portal. Those fields give a scammer what they need to pose as the customer's own power company.
The Watch · Security desk
What happened
- Alabama Power has roughly 100,000 affected accounts out of the 1.6 million it serves.
- Mississippi Power is named as affected in Southern Company's public notice, but no customer count has been released for it.
- Southern Company says the attacker did not reach bank account numbers, payment card numbers or driver's license numbers.
- Notices are going out to affected customers by mail and email, along with an offer of one year of credit monitoring at no cost.
Why it matters
- constraint A year of credit monitoring watches for new credit opened in a customer's name. It will not flag a call or email from someone posing as the utility.
- exposure Customers whose last four SSN digits were exposed can be impersonated anywhere those digits are accepted as proof of identity, well beyond their utility account.
- decision Until Southern Company says how the portal was entered, customers cannot know whether changing their portal password addresses the cause or only their own account.
The state figures already add up to the company's total. Georgia Power's and Alabama Power's counts come to roughly 400,000 together [12], so Mississippi Power's share fits inside the rounding of the headline number. Georgia alone is three quarters of the total [13]. In Alabama, the affected accounts are 6.25 percent of the subsidiary's base, about one account in 16 [11].
The public notice lists the fields. "Based on our investigation to date, the limited customer account information that the unauthorized party gained access to includes the customer's name, mailing address, phone number, email, or the last 4 digits of their Social Security Number, and other basic account details," the notice says [7]. The "or" in that list means not every customer lost every field.
Southern Company has not said when the intrusion took place or how the attacker got into the portal [9]. "An unauthorized third party accessed certain, limited information about the accounts of approximately 400K customers. Upon detection, we took immediate steps to stop the activity and have engaged law enforcement," the company said in a statement to the media [6].
Southern Company runs electric utilities in three states and gas distribution businesses in four, serving more than 9 million customers [2]. Everything it has disclosed about this incident concerns customer records reached through a customer-facing website [1][7]. On that evidence this is a consumer data breach at a utility. It is not evidence that self-service portals open a path into the systems that run generation or the grid.
What to watch
- Southern Company's explanation of how the portal was entered, reused customer passwords or a flaw in the application, and the dates of the intrusion.
- A Mississippi Power count, or a revised total if it moves the figure past roughly 400,000.
- A named actor or claim of responsibility, to show whether this is a one-off or part of a sustained run at utility customer systems.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Southern Company is notifying roughly 400,000 customers that their utility account information was accessed by an unauthorized third party through its online customer portal.
- [2]
Atlanta-based Southern Company serves more than 9 million customers through electric utilities in three states and natural gas distribution businesses in four; its electric subsidiaries are Georgia Power, Alabama Power and Mississippi Power.
- [3]
Roughly 300,000 of the affected accounts belong to Georgia Power customers.
- [4]
According to Southern Company, the incident impacted roughly 100,000 of Alabama Power's 1.6 million accounts.
- [5]
Mississippi Power is named as affected in the company's public notice, but no figure has been released for its customers.
- [6]
"An unauthorized third party accessed certain, limited information about the accounts of approximately 400K customers. Upon detection, we took immediate steps to stop the activity and have engaged law enforcement."
- [7]
"Based on our investigation to date, the limited customer account information that the unauthorized party gained access to includes the customer's name, mailing address, phone number, email, or the last 4 digits of their Social Security Number, and other basic account details."
- [8]
The utility says the attacker did not access bank account numbers, payment card numbers or driver's license numbers.
- [9]
Southern Company has not said when the intrusion took place or how the attacker gained access to the portal.
- [10]
Impacted customers are being notified by mail and email and offered a year of free credit monitoring.
- [11]
Alabama Power's roughly 100,000 affected accounts are 6.25 percent of its 1.6 million accounts, about one in 16.
- [12]
Georgia Power's and Alabama Power's counts together equal roughly the full 400,000 total, so Mississippi Power's unreported count falls within the rounding of the headline figure.
- [13]
Georgia Power customers are about three quarters of the roughly 400,000 affected accounts.
Sources
1 independent publisher whose own reporting we read for this story.
- securityweek.comGeorgia Power, Alabama Power Data Breach Hits 400,000 Accounts
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Utility cybersecurityFollow
- Data BreachesFollow
Entities
- Southern CompanyFollow
- Georgia PowerFollow
- Alabama PowerFollow
- Mississippi PowerFollow