Select a theme from the list.
Insights

From our experts

Latest
MatchBoil Evolves Into a Stealthier Espionage Tool Against Ukraine's Essential IndustriesFBI Domain Seizures Cut Into Flax Typhoon's Global Hacking PlatformActive Directory Defenses Face an 11-Hour Race to Protect Tier 0Southern Company Portal Breach Exposes 400,000 Utility AccountsRegistry Hijacks Expose a Dangerous Weak Link Beneath HTTPS TrustRansomware Recovery CEO Accused of Hiding Millions in Secret PaymentsAlleged Ploutus Developer Arrested as ATM Jackpotting Crackdown Reaches Malware LeadershipRogue AI Agents Tested Wikimedia's Boundaries and Tried to Turn Web Tools Into ProxiesPwn2Own Researchers Break 32 Zero-Days Across Phones, AI Systems and Smart DevicesEmergency Exchange Update Closes a Door Into Other Users' MailboxesApple Moves to Rein In AI Agents With Sweeping Mac Data AccessPredictable Session Keys Put Rejetto File Servers on the Attack RadarMatchBoil Evolves Into a Stealthier Espionage Tool Against Ukraine's Essential IndustriesFBI Domain Seizures Cut Into Flax Typhoon's Global Hacking PlatformActive Directory Defenses Face an 11-Hour Race to Protect Tier 0Southern Company Portal Breach Exposes 400,000 Utility AccountsRegistry Hijacks Expose a Dangerous Weak Link Beneath HTTPS TrustRansomware Recovery CEO Accused of Hiding Millions in Secret PaymentsAlleged Ploutus Developer Arrested as ATM Jackpotting Crackdown Reaches Malware LeadershipRogue AI Agents Tested Wikimedia's Boundaries and Tried to Turn Web Tools Into ProxiesPwn2Own Researchers Break 32 Zero-Days Across Phones, AI Systems and Smart DevicesEmergency Exchange Update Closes a Door Into Other Users' MailboxesApple Moves to Rein In AI Agents With Sweeping Mac Data AccessPredictable Session Keys Put Rejetto File Servers on the Attack Radar
Security Insight

Southern Company Portal Breach Exposes 400,000 Utility Accounts

Southern Company Portal Breach Exposes 400,000 Utility Accounts
Photo by Ann H on Pexels

Southern Company is notifying approximately 400,000 customers after an unauthorized party accessed information through its online customer portal. The incident affected roughly 300,000 Georgia Power accounts and 100,000 Alabama Power accounts, with exposed details potentially including contact information and partial Social Security numbers.

A breach involving Southern Company's online customer portal has exposed account information belonging to approximately 400,000 utility customers, creating identity fraud and targeted phishing risks across several southern US states.

Customer data accessed through online portal

Southern Company operates electric utilities including Georgia Power, Alabama Power and Mississippi Power. The company said an unauthorized third party obtained access to limited customer account information before the activity was detected and stopped.

Approximately 300,000 affected accounts belong to Georgia Power customers, while another 100,000 are associated with Alabama Power. Mississippi Power was also identified in the public notice, although the company did not provide a separate number of affected customers for that subsidiary.

The accessed information may include customer names, mailing addresses, telephone numbers, email addresses, basic account details and the final four digits of Social Security numbers. Southern Company said bank account numbers, payment card information and driver's license numbers were not accessed.

The company has not publicly explained how the attacker entered the portal or when the unauthorized activity began. Law enforcement has been engaged, and affected customers are being offered one year of credit monitoring.

Limited data can still support convincing fraud

The absence of complete financial records does not eliminate the danger. Utility account details are highly useful for social engineering because criminals can combine names, addresses, contact information and partial identity numbers to make fraudulent messages appear authentic.

Attackers could impersonate a utility representative, claim that a payment failed or threaten service disconnection. They may also use the exposed information to target customer service processes and attempt account recovery or profile changes.

Recommended actions

  • Customers should independently verify unexpected payment or disconnection notices.
  • Passwords reused on other services should be changed immediately.
  • Multifactor authentication should be enabled if the customer portal supports it.
  • Utility providers should review login telemetry, recovery workflows and automated abuse detection.
  • Organizations should limit the amount of personal data visible through customer-facing portals.

In my view, the unanswered question is whether the portal was compromised through stolen credentials, automated account attacks or an application weakness. Each possibility requires a different response. Southern Company should eventually provide enough technical detail to help customers and other utility operators understand the failure. Critical service providers hold unusually trusted relationships with consumers, making even basic account information valuable to criminals.

Talk to our team →

Latest

MatchBoil Evolves Into a Stealthier Espionage Tool Against Ukraine's Essential IndustriesOct 9, 2026FBI Domain Seizures Cut Into Flax Typhoon's Global Hacking PlatformOct 9, 2026Active Directory Defenses Face an 11-Hour Race to Protect Tier 0Oct 9, 2026Southern Company Portal Breach Exposes 400,000 Utility AccountsOct 8, 2026Registry Hijacks Expose a Dangerous Weak Link Beneath HTTPS TrustOct 8, 2026Ransomware Recovery CEO Accused of Hiding Millions in Secret PaymentsOct 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards