Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts

Southern Company is notifying customers that their utility account information was accessed by hackers.

Electric utility hacked

Southern Company is notifying roughly 400,000 customers that their utility account information was accessed by an unauthorized third party through its online customer portal.

The Atlanta-based energy holding company serves more than 9 million customers through electric utilities in three states and natural gas distribution businesses in four. Its electric subsidiaries are Georgia Power, Alabama Power and Mississippi Power.

Roughly 300,000 of the affected accounts belong to Georgia Power customers. According to Southern Company, the incident also impacted roughly 100,000 of Alabama Power’s 1.6 million accounts.

Mississippi Power is named as affected in the company’s public notice, but no figure has been released for its customers.

“An unauthorized third party accessed certain, limited information about the accounts of approximately 400K customers. Upon detection, we took immediate steps to stop the activity and have engaged law enforcement,” the company said in a statement sent to the media.

Southern Company’s public notice specifies the type of data involved. “Based on our investigation to date, the limited customer account information that the unauthorized party gained access to includes the customer’s name, mailing address, phone number, email, or the last 4 digits of their Social Security Number, and other basic account details,” the notice reads.

Advertisement. Scroll to continue reading.

The utility says the attacker did not access bank account numbers, payment card numbers or driver’s license numbers.

Southern Company has not said when the intrusion took place or how the attacker gained access to the portal.

Impacted customers are being notified by mail and email and offered a year of free credit monitoring.

Related: ASOS Confirms Cyberattack, Data Breach

Related: Advantest Discloses Data Breach Months After Ransomware Attack

Related: 8.8 Million Impacted by Data Breach at Denmark’s Central Person Register

Related: Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Rapid7 has named Rik Ferguson as VP of Security Intelligence.

Cytactic has appointed Tim Brown as CSO.

Scott Simkin has joined Vega as CMO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.