Southern Company — the Atlanta-based utility holding company behind Georgia Power, Alabama Power, and other regulated electric and gas brands — confirmed that an unauthorized third party accessed its shared online customer portal, exposing personal information tied to roughly 400,000 customer accounts. Reporting on October 5, 2026 from NBC15, FOX10 News, and Rough Draft Atlanta aligns with company statements: about 300,000 Georgia Power accounts and about 100,000 Alabama Power accounts sit in scope. Southern Company detected suspicious activity recently, stopped it, notified law enforcement, and says investigators have no evidence of ongoing access. Canonical record: https://breachhistory.com/southern-company/southern-company-portal2026 (/southern-company/southern-company-portal2026).
This is a verified Southern Company data breach narrative routed through local news quoting utility spokespeople — not a ransomware leak-site listing. What this is not, according to those statements: a compromise of full Social Security numbers, bank account numbers, payment card data, or driver’s licenses. Alabama Power serves on the order of 1.6 million customers; the disclosed Alabama count implies roughly 6% of that base received exposure notices — a meaningful slice even when grid operations and payment rails were not the stated target.
What happened in the Southern Company portal breach
Southern Company operates a centralized digital front door where customers manage billing profiles, service addresses, and account metadata across operating companies. Attackers reached that portal environment as an unauthorized third party — the public statements BreachHistory indexed do not name a ransomware brand, a stolen VPN credential, or a specific software CVE. FOX10 and NBC15 describe the incident as a data breach affecting portal-held customer information rather than a reported shutdown of generation or transmission systems.
Georgia Power and Alabama Power are notifying subsets of their populations with different absolute counts but the same structural story: contact and identity fragments useful for fraud and spear-phishing, plus partial tax identifiers. Rough Draft Atlanta’s October 5 coverage emphasizes Georgia Power’s ~300,000 figure and situates the event in the same news cycle as other U.S. utility customer-data disclosures — including CenterPoint Energy’s September 2026 SEC filing, where a Houston-based utility confirmed customer personal information theft through an external-facing system while keeping delivery operations running.
Southern Company’s holding-company structure matters for readers asking was I affected. If you only receive gas service from a Southern subsidiary not named in early reporting, wait for your operating company’s letter rather than assuming the 400,000 total covers every brand in the portfolio. The October 5 articles BreachHistory indexed focus on Georgia Power and Alabama Power headcounts.
Timeline — October 2026 disclosure window
- Before October 5, 2026 — Southern Company detects suspicious activity in the online customer portal, contains access, and engages law enforcement (exact discovery date not published in indexed local news summaries).
- October 5, 2026 — Alabama Power tells NBC15 that ~100,000 customers are affected; FOX10 publishes Southern Company’s broader confirmation; Rough Draft Atlanta reports ~300,000 Georgia Power accounts in scope.
- October 5–6, 2026 — Notification and credit-monitoring enrollment materials begin reaching households (specific mailing waves not itemized in trade summaries).
- Ongoing — Law enforcement and internal forensics continue; Southern Company publicly states no evidence attackers still hold live access at disclosure time.
What remains unknown publicly
- Exact intrusion vector — credential stuffing, session hijack, API abuse, insider-assisted access, or third-party software flaw — not attested in indexed October 5 reporting.
- Whether business customers and residential accounts split evenly within the 300k / 100k buckets.
- Dwell time — how long unauthorized parties browsed portal records before detection.
- Whether other Southern operating companies beyond Georgia Power and Alabama Power will add counts later.
What was exposed in the Georgia Power and Alabama Power breach
Company statements carried by NBC15, FOX10, and Rough Draft Atlanta describe the following categories for affected portal accounts:
- Names
- Service and mailing addresses
- Phone numbers
- Email addresses
- Last four digits of Social Security numbers for individuals, or last four digits of tax identification numbers for business accounts
- Other basic account details maintained in the portal (specific field lists may appear on individual notification letters)
That mix is classic utility-account fraud fuel. Criminals pair real names with real service addresses to craft convincing past-due bill texts, fake rate-relief calls, and “verify your Georgia Power autopay” emails. Email plus phone enables multi-channel harassment. Last-four SSN or tax-ID fragments help attackers pass weak knowledge-based authentication on unrelated sites that still ask for partial identifiers.
Business accounts with tax-ID tails in scope should watch vendor-payment redirection scams — attackers who know your legal entity name and utility relationship may impersonate accounts payable staff.
What was not exposed — read the limits carefully
Southern Company’s public messaging, as relayed by FOX10 and peer outlets on October 5, draws a bright line around high-impact financial identifiers. According to those reports, the breach did not include:
- Full Social Security numbers
- Bank account numbers
- Payment card numbers
- Driver’s license numbers
To be clear: “not included” in a day-one press statement is not a guarantee nothing else will appear on your personal notification PDF. Always treat the letter in your mailbox as authoritative for field-level detail. Still, the corporate emphasis on excluding full SSNs and payment instruments matters — it tells consumers the immediate panic about autopay bank drafts being published wholesale is not what the utility is asserting.
Grid control systems and operational technology are also not described as impacted in indexed reporting. This event reads like customer-information governance and portal security, not a Stuxnet-style industrial compromise — similar to how CenterPoint framed customer PII theft separately from electric delivery continuity.
Who is at risk after the Southern Company breach 2026
Georgia Power customers whose accounts appear in the ~300,000 cohort should expect direct notification and enrollment instructions for identity services.
Alabama Power customers in the ~100,000 cohort face parallel risks with a disclosed offer of one year of credit monitoring and identity-theft restoration services per NBC15’s summary of company coverage — read your letter for activation codes and deadlines.
Former customers whose portal profiles remained active could still be in scope if statements reference historical account metadata; retention policies vary by utility program.
Household members whose names are not on the bill but share addresses or phone numbers may receive secondary phishing even without a formal notice — attackers target the whole household when service addresses leak.
Landlords and property managers with master-meter or multi-unit billing profiles should scrutinize portal users and password reuse across tenants’ ticket systems.
Phishing scenarios tied to utility data
- Fake shutoff threats citing your real street address and account name — utilities send warnings, but they do not demand instant cryptocurrency payment by text.
- “Refund for overbilling” links harvesting portal credentials — Southern Company will not ask you to re-login from an SMS short link after a breach.
- Credit monitoring impersonators asking for full SSN to “activate” services — enrollment should follow instructions on your official letter only.
- Business email compromise referencing Alabama Power or Georgia Power vendor relationships to redirect ACH payments.
How the attack might have worked — without guessing beyond sources
Indexed October 5 articles do not publish forensic diagrams. Security teams outside Southern Company should avoid filling the gap with rumor. Plausible utility-portal paths — listed here as industry context, not as confirmed facts for this incident — include stolen customer passwords reused from other sites, session token theft on shared devices, vulnerable web components in customer self-service stacks, or compromised contractor credentials with portal admin rights.
Southern Company’s statement that access was detected, stopped, and is not ongoing suggests containment succeeded at the application or account layer rather than a prolonged database exfiltration still running at press time. That does not automatically mean exfiltration did not occur earlier; it means the utility is not asserting attacker persistence when journalists asked on October 5.
Utility sector context — customer portals under pressure
U.S. electric and gas brands hold some of the most stable customer relationships in the economy — addresses rarely change, bills arrive monthly, and brand trust is high. That stability makes utility portals attractive targets for credential thieves and for fraudsters who never need OT access to monetize stolen PII.
The CenterPoint Energy breach established a recent template: confirm customer data theft, keep electrons flowing, offer monitoring, and file investor disclosures. Southern Company’s October 2026 episode adds another large southeastern footprint to that pattern with explicit Georgia and Alabama splits. Internationally, massive identity events such as the Denmark CPR breach show how even partial national identifiers cascade into fraud — different sector, same lesson that address plus identifier fragments scale badly.
Education and retirement sectors saw parallel third-party and application-layer exposures in autumn 2026 — for example Frontline Education’s third-party software vulnerability hitting school employee SSNs, and TIAA’s September regulator notice for customer Social Security numbers. None of those are the same incident as Southern Company’s portal; they illustrate how consumers must track multiple notification letters simultaneously.
Japan’s Times Car breach is unrelated geographically but shows rental and mobility brands joining utilities in disclosing multi-million account counts — fraudsters happily cross-pollinate datasets by region when building call scripts.
What Southern Company, Georgia Power, and Alabama Power said
FOX10’s October 5 piece quotes Southern Company acknowledging unauthorized third-party access to the online customer portal and describing remediation and law enforcement coordination. NBC15 centers Alabama Power’s spokesperson confirming ~100,000 customers affected and outlining identity-theft restoration and credit monitoring for a one-year period. Rough Draft Atlanta translates Georgia Power’s ~300,000 figure for metro readers who may not follow holding-company naming conventions.
Common threads across outlets: detection of suspicious activity, cessation of unauthorized access, no evidence of continuing intrusion at disclosure time, and customer outreach beginning immediately. None of the indexed stories attribute the incident to a named cybercrime group or cite a ransom demand — treat it as a conventional corporate breach disclosure unless Southern Company publishes attribution later.
Credit monitoring and identity restoration
Alabama Power’s coverage, as summarized by NBC15, includes one year of credit monitoring and identity-theft restoration for affected customers. Georgia Power customers should rely on notification letters for parallel program details — Rough Draft Atlanta confirms exposure scale but BreachHistory indexed the one-year monitoring language most explicitly for Alabama Power in NBC15’s reporting.
Practical enrollment advice:
- Activate monitoring only through URLs and phone numbers printed on your official letter — not through search ads or cold calls.
- Mark calendar reminders before the complimentary year expires if you want to pay for continuation.
- Pair monitoring with free credit freezes at major bureaus if you want proactive blocking, not just post-fraud alerts.
What you should do — action items
- Watch for Georgia Power or Alabama Power mail and email — notifications may stagger over days.
- Enroll in offered credit monitoring before any deadline on your letter.
- Log in to your utility portal via typed URLs (customer portals you already bookmark) to review contact info and authorized users; do not trust links in unsolicited messages.
- Change portal passwords if you reused them elsewhere; enable multifactor authentication if the operating company offers it.
- Place fraud alerts or credit freezes if you want extra protection beyond monitoring — especially if last-four SSN exposure worries you on financial sites with weak KBA.
- Report suspicious shutoff calls to your operating company’s published customer service line, not callback numbers provided by callers.
- Business accounts: brief AP teams on wire-change social engineering that cites utility relationships.
- Document identity theft attempts — restoration services tied to the breach may require incident logs.
Regulatory and legal outlook
Utility breaches typically trigger state breach-notification laws across customers’ residencies, not only headquarters states. Georgia and Alabama attorneys general may receive filings as notifications widen. Southern Company is a large cap regulated utility; expect potential follow-on investor disclosures if materiality thresholds require — unlike CenterPoint’s September 8-K path, BreachHistory had not indexed an SEC form specifically for Southern Company at draft time on October 6.
Class-action marketing often follows regional news cycles. Verify any law firm claiming to represent you against Southern Company before sharing additional personal data.
Technical notes for enterprise defenders
If you defend another utility or critical infrastructure operator, use this incident as a tabletop prompt rather than copying unconfirmed TTPs:
- Map which portal APIs return partial SSN or tax-ID fields and whether audit logs capture bulk enumeration.
- Review session timeout, device binding, and step-up authentication before displaying tax identifiers.
- Test whether customer service representatives can override authentication with last-four SSN alone — post-breach, that practice helps attackers.
- Coordinate fraud desk messaging with comms so customers hear consistent guidance on shutoff scams.
Georgia Power vs Alabama Power — two brands, one portal architecture
Customers sometimes assume Georgia Power and Alabama Power are unrelated competitors. Under Southern Company, they share corporate cybersecurity investment even while regulators and rate cases differ. A portal breach spanning both brands suggests compromise at shared digital infrastructure or credentials with cross-brand scope — exact architecture is not public, but the joint disclosure implies centralized online services rather than two fully isolated stacks.
Ratepayers should not cancel autopay out of panic unless their letter instructs them to — excluded bank and card data means the immediate risk model is identity fraud and phishing, not published payment instruments according to October 5 statements.
Comparison with CenterPoint Energy (September 2026)
CenterPoint confirmed customer PII theft via an external-facing system in an SEC 8-K; Southern Company’s October narrative emphasizes portal access with explicit ~400,000 account math split across Georgia and Alabama. Both utilities stress continued delivery operations. CenterPoint’s total affected population was still under investigation in early reporting; Southern Company published rounded operating-company counts on day one. Customers in multi-state households should read each letter on its own merits.
If you do not receive a notice
Absence of mail by mid-October does not prove your account was untouched if notifications batch by region. If you are an active portal user in Georgia or Alabama service territories and believe you should be included, call customer service through official numbers on your printed bill — not numbers from breach-themed social posts.
Households below the 400,000 total still face phishing if attackers scrape news and guess addresses in Atlanta or Birmingham metros. Generic caution applies even without a letter.
Why partial SSN exposure still matters
Security practitioners sometimes dismiss last-four leaks because many systems require more digits. Fraudsters disagree. They combine last-four with addresses from the same breach to answer security questions, impersonate you to mobile carriers, or pre-fill credible scam scripts. Business tax-ID tails enable targeted BEC against finance teams who recognize the utility vendor name.
Southern Company’s exclusion of full SSNs reduces catastrophic single-field identity takeover risk relative to incidents like TIAA’s full SSN disclosure, but it does not reduce phishing quality — scammers now know you are a real Georgia Power or Alabama Power customer.
Family and elderly ratepayers
Utility scams disproportionately succeed against seniors who fear losing air conditioning in southern summers or heat in rare cold snaps. Coach relatives that legitimate utilities provide written notice and official portals for payment changes. No one legitimate demands gift cards to prevent shutoff within an hour.
Caregivers managing portal access for aging parents should verify whether compromised profiles include authorized payor emails that attackers could password-reset.
Canonical record and primary sources
BreachHistory indexes this row as company-confirmed with ~400,000 accounts across Georgia Power and Alabama Power. Bookmark /southern-company/southern-company-portal2026 for updates if Southern Company revises counts or adds operating companies.
- NBC15 — Alabama Power ~100,000 customers affected (Oct 5, 2026)
- FOX10 — Southern Company portal breach (Oct 5, 2026)
- Rough Draft Atlanta — ~300,000 Georgia Power accounts (Oct 5, 2026)
Long-term identity hygiene for utility customers
Even after complimentary monitoring expires, keep transaction alerts on bank accounts tied to autopay, retain paper bills long enough to spot duplicate account numbers, and shred old statements that repeat service addresses. Utility breaches recur industry-wide; the portal password you set today should be unique and long.
When Southern Company publishes additional forensic detail — attribution, CVE, or expanded field lists — update your personal risk assessment. The October 5 facts already justify enrolling monitoring, hardening portal credentials, and treating energy-brand outreach as potentially spoofed until verified through official channels.