Georgia Power, Alabama Power Portal Breach Hits 400,000 Accounts

An unauthorized party accessed the Georgia Power and Alabama Power customer portal, exposing about 400,000 accounts, including partial SSNs and contact data.
Table of Contents
    Add a header to begin generating the table of contents

    An unauthorized party gained access to the online customer portal used by Georgia Power and Alabama Power, exposing personal information tied to about 400,000 customer accounts, the Southern Company utilities disclosed on October 7.

    The affected accounts break down to about 300,000 at Georgia Power and about 100,000 at Alabama Power. The disclosure also mentions Mississippi Power but gives no figure for it.

    What Information the Portal Intruder Obtained

    The exposed data includes customers’ names, mailing addresses, phone numbers, email addresses, the last four digits of Social Security numbers, and basic account details. That set of information is enough to support targeted phishing messages that reference real account details.

    Data That Was Not Exposed

    According to the disclosure, bank account numbers, payment card numbers and driver’s license numbers were not exposed. The distinction limits the direct financial exposure from the breach, though the partial Social Security numbers and contact information still carry identity-fraud risk.

    Unanswered Questions About the Intrusion

    The utilities have not said how the unauthorized party got into the customer portal. The disclosure also does not specify when the intrusion took place or how long the party had access.

    Those gaps mean customers cannot tell from the public statement how long their information was reachable. The disclosure describes the access as stopped, which indicates the utilities closed the route the intruder used, without explaining what it was.

    Mississippi Power Mentioned Without a Figure

    The disclosure refers to Mississippi Power but provides no count of affected accounts for it. The roughly 400,000 total therefore reflects only the Georgia Power and Alabama Power figures stated.

    Company Response and Customer Protections

    The utilities say the unauthorized activity has stopped and that law enforcement has been engaged. They are notifying affected customers by mail and email and are offering one year of credit monitoring.

    Phishing and Identity Fraud Risk

    With about 400,000 customers affected, the main exposure is to fraud that draws on the leaked details. A message that cites a customer’s name, address and last four digits of their Social Security number can appear credible, and attackers commonly use such details to build convincing phishing attempts or to support identity theft. The disclosure does not report any misuse so far.

    Southern Company’s disclosure states that the intruder reached the portal, and that the utilities have since stopped the activity. The company engaged law enforcement, and its notifications to customers arrive by mail and by email. The credit monitoring on offer lasts one year, which is the main protection the utilities have announced for customers whose partial Social Security numbers were exposed.

    Why Utility Customer Portals Draw Attacks

    Customer portals hold records for large numbers of households under a single login system, which makes them an efficient target for anyone who wants personal data in volume. In this case a single portal exposed accounts across two separate utilities, indicating that the portal serves several Southern Company subsidiaries.

    The disclosure describes unauthorized access to the customer portal and does not mention operational systems.

    The disclosure breaks the affected accounts into two figures: about 300,000 at Georgia Power and about 100,000 at Alabama Power. It also mentions Mississippi Power without giving a number, so the final tally could differ from the 400,000 headline figure. The utilities have not said whether the intruder downloaded the data in bulk or viewed it account by account.

    The utilities’ decision to name the categories of data both exposed and not exposed gives customers a clear basis for judging their risk. Customers who receive a notification can expect it to arrive by mail or email, along with instructions for the year of credit monitoring the utilities are providing.

    Related Posts