An unauthorized third party accessed Southern Company’s online customer portal, exposing information associated with approximately 300,000 Georgia Power accounts and 100,000 Alabama Power accounts. Mississippi Power customers were also affected, but their number was not disclosed. Exposed data included customer contact information, the last four digits of Social Security numbers, and other basic account details. The company said bank account, payment card, and driver’s license numbers were not accessed. The intrusion reportedly occurred in September, but the exact incident date and entry method remain undisclosed.
Southern Company said its monitoring systems detected the intrusion, it stopped the unauthorized access, and it notified law enforcement. Affected customers are being notified by mail and email and offered one year of free Equifax credit monitoring. The company also warned customers about fraudulent utility-related communications; the exposed contact and account information could enable more convincing phishing and impersonation attempts.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Southern Company publicly disclosed the breach and identified Georgia Power, Alabama Power, and Mississippi Power as affected subsidiaries. It did not disclose the exact intrusion date or how the attacker gained access.
An unauthorized third party accessed Southern Company's customer portal, exposing approximately 300,000 Georgia Power accounts and 100,000 Alabama Power accounts; Mississippi Power was also affected, but its count was not disclosed. Accessed information included customer contact details, the last four digits of Social Security numbers, and basic account details, but not bank account, payment card, or driver's license numbers.
Southern Company began notifying affected customers by mail and email and offering one year of free Equifax credit monitoring. It also established an assistance line and warned customers about fraudulent utility-related communications.
Southern Company notified law enforcement about the customer portal breach as part of its incident response.
Southern Company's monitoring systems detected the unauthorized activity, and the company took immediate steps to stop it. The company subsequently reported finding no evidence of ongoing unauthorized access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcesecurityweek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.