Quick Answer
Southern Company says unauthorized access to its customer portals affected about 400,000 accounts across Georgia Power, Alabama Power, and Mississippi Power. Exposed data includes contact information and the last four Social Security number digits, but Georgia Power says bank, card, and driver’s-license numbers were not involved. Watch for official notices, use the offered credit monitoring, and verify any payment request independently.
Key Takeaways
- Southern Company says the incident affected approximately 400,000 customer accounts.
- Georgia Power says about 300,000 of its customer accounts were affected.
- Names, addresses, phone numbers, email addresses, and the last four Social Security number digits were exposed.
- Georgia Power says bank-account numbers, payment-card numbers, and driver’s-license numbers were not involved.
- Georgia Power is notifying affected customers and offering one year of Equifax credit monitoring.
What happened in the Southern Company data breach?
Southern Company says an unauthorized third party accessed utility customer portals and affected approximately 400,000 customer accounts. The incident involves Georgia Power, Alabama Power, and Mississippi Power, three Southern Company electric utilities operating in the Southeast. SecurityWeek’s report on the multi-utility incident identifies the broader scope and the affected companies.
Georgia Power said the unauthorized access affected about 300,000 of its own customer accounts. Alabama Power accounts make up about 100,000 of the total, while Mississippi Power had not released an account count as of October 7, 2026. The reported figures explain why customers of all three electric utilities should review communications carefully, even though the available details are more specific for Georgia Power.
Southern Company serves more than 9 million customers through electric utilities in three states and gas-distribution businesses in four states. The disclosed incident concerns the named electric-utility customer portals, not every Southern Company customer. Customers should avoid assuming that a Southern Company relationship alone confirms exposure and instead wait for a direct notice from the applicable utility.
Which Southern Company utility customers were affected?
Southern Company says the affected utility customer groups include Georgia Power, Alabama Power, and Mississippi Power customers. Georgia Power disclosed the largest known count, at about 300,000 accounts, while Alabama Power accounts account for about 100,000 of the reported total. Mississippi Power is included in the incident, but no public account count had been released.
| Utility | Reported status | Known account count | What customers should do |
|---|---|---|---|
| Georgia Power | Customer portal access was affected | About 300,000 accounts | Review email and mail notices from Georgia Power |
| Alabama Power | Included in the broader Southern Company incident | About 100,000 accounts | Monitor official utility communications |
| Mississippi Power | Included in the broader Southern Company incident | No public count released | Monitor official utility communications |
Southern Company utility customers should treat the account count as a reported incident scope, not as proof that every account holder had the same information exposed. The information released publicly identifies the affected utilities and the overall account total, but it does not establish that every customer record contained identical fields. The practical response is to read any notification fully and compare it with the account details you maintain.
What customer data was exposed in the Southern Company breach?
Georgia Power says the exposed information includes names, addresses, phone numbers, email addresses, and the last four digits of Social Security numbers. Georgia Power’s disclosed customer-response details, reported by WTVM, also state that the company is contacting affected customers by email and mail.
The combination of contact details and partial Social Security information can make an impersonation attempt appear more credible because a scammer may already know basic account-holder information. The disclosed fields do not include a full Social Security number, based on the information released so far. That limitation reduces the known scope of the exposure, but it does not eliminate the need to treat unexpected messages about an electric bill with caution.
Customers should preserve legitimate notices and check the sender, address, and account references before responding. A message that contains accurate personal details is not automatically genuine. Customers who want to reduce the risk of reused credentials should also review how they manage account logins, including whether a password manager’s free plan provides a practical way to keep unique passwords for utility and other accounts.
Were bank accounts, card numbers, or driver’s licenses involved?
Georgia Power says bank-account numbers, payment-card numbers, and driver’s-license numbers were not involved in the disclosed incident. That distinction matters because the known data set does not include the direct payment credentials that customers commonly use to pay utility bills. Customers do not need to assume that a payment card or bank account was exposed solely because they received a breach notice.
The Southern Company breach still requires attention because names, addresses, phone numbers, email addresses, and partial Social Security information can support targeted scam attempts. The practical risk is not limited to direct financial theft from a card number. A criminal can use familiar account details to create a convincing call, email, or text that pressures a customer to provide additional information or make an immediate payment.
Customers should not provide account credentials, full Social Security numbers, or payment information in response to an unexpected contact. Customers who see unfamiliar activity in a financial account should contact the bank or card issuer using the number on a statement or the official app, rather than any number included in an unsolicited message.
How is Georgia Power notifying affected customers?
Georgia Power says it is notifying affected customers by email and mail and offering one year of free credit monitoring through Equifax. The notification process gives affected customers a direct way to confirm whether Georgia Power identified their account in the incident. Customers should read both the email and mailed notice because the information may explain eligibility and the available enrollment process.
Georgia Power spokesperson Tiffany Anthony said the company stopped the activity, involved law enforcement, and found no evidence of continuing unauthorized access. The statement addresses whether the company had identified active access at the time of disclosure, but it does not remove the need for customers to watch for later scam attempts using already exposed information.
Customers should use contact details from a verified Georgia Power notice or from the utility’s established account channels. Do not rely on a link or phone number from a message that arrives unexpectedly. Similar caution is useful after other consumer-data incidents, including the investor data exposure at DriveWealth, because breach notices can create opportunities for impersonators as well as legitimate companies.
How can the Southern Company breach lead to utility payment scams?
Southern Company customer information can make a utility impersonation scam more persuasive because a caller or message sender may know a customer’s name, address, phone number, email address, or partial Social Security information. Georgia Power warned that the company will never threaten an immediate service shutoff or demand payment by phone. Georgia Power’s scam warning, reported by Quartz, is especially relevant after the customer-portal incident.
Customers should end a suspicious call instead of debating whether it is real. Open the utility’s normal website independently, use the number on a recent bill, or sign in through the established customer portal to check the account status. A caller’s knowledge of an account holder’s address or partial Social Security number does not verify that the caller works for the utility.
Customers should also be cautious with email and text links that claim an account is overdue or a payment method must be updated. A suspicious link can direct a customer to a fake sign-in page designed to collect credentials. The most sensible approach is to enter the utility website address yourself or use an existing official app, rather than following an urgent message.
What should Southern Company customers do now?
Southern Company utility customers should first wait for or review an official notice from Georgia Power, Alabama Power, or Mississippi Power, then use the stated credit-monitoring offer if they are eligible. The offer applies to affected Georgia Power customers under the disclosed response plan. Customers should keep a copy of the notice and follow its enrollment instructions through verified channels.
- Review utility email and physical mail for an official breach notification.
- Use the Equifax credit-monitoring offer if the official notice says your account is eligible.
- Verify utility billing questions through the official account portal, a recent bill, or a known customer-service number.
- Ignore threats of immediate shutoff and do not provide payment information during an unsolicited call.
- Change a utility-account password if you reused that password on other services.
Southern Company customers should focus on account verification and scam resistance rather than assuming a specific financial account has been compromised. The reported data did not include bank-account, payment-card, or driver’s-license numbers, according to Georgia Power. Customers who receive a message requesting urgent payment should stop and verify the request through an independent official channel before sharing information or sending money.
Customers who believe an account has been accessed should contact the relevant utility through its official support path. Customers who identify unauthorized financial transactions should stop using the suspicious communication and contact the financial institution directly. Do not attempt to resolve a possible fraud issue solely through an unexpected caller, text, or email sender.
FAQ
Did the Southern Company data breach expose full Social Security numbers?
Southern Company breach disclosures identify the last four digits of Social Security numbers as exposed, not full Social Security numbers. Georgia Power also says bank-account numbers, payment-card numbers, and driver’s-license numbers were not involved.
Which utilities were involved in the Southern Company data breach?
Southern Company says Georgia Power, Alabama Power, and Mississippi Power were involved in the customer-portal incident. Georgia Power reported about 300,000 affected accounts, Alabama Power accounted for about 100,000, and Mississippi Power had not released a public count.
Will Georgia Power contact affected customers?
Georgia Power says it is notifying affected customers by email and mail. Georgia Power also says it is offering one year of free credit monitoring through Equifax.
Can Georgia Power demand payment by phone after the breach?
Georgia Power says it will not threaten immediate shutoff or demand payment by phone. Customers should verify any billing request through an official account portal, a recent bill, or a known utility phone number.
What should customers do after receiving a Southern Company breach notice?
Southern Company utility customers should review the official notice, use the available credit-monitoring offer if eligible, and watch for impersonation attempts. Customers should not provide passwords or payment details through an unsolicited call, text, or email.
