Skip to main content

Morning Overview

Southern Company says about 300,000 Georgia Power customers were caught in a portal breach

Southern Company’s statement on the portal incident covers approximately 400,000 customer accounts, and about 300,000 of those belong to Georgia Power. Alabama Power accounts for roughly 100,000 more. The exposed fields include names, addresses, phone numbers, email addresses and the last four digits of Social Security numbers, a combination that is thin on its own but useful for anyone building a convincing impersonation.

The disclosure surfaced on Oct. 5, 2026, and local stations in Alabama and Georgia carried it within hours. Georgia Power is the larger share by a wide margin, since its customer base of roughly 2.8 million dwarfs Alabama Power’s 1.6 million, and the 300,000 affected Georgia accounts therefore represent a little over a tenth of its total base, while the 100,000 at Alabama Power are closer to one in sixteen.

The portal and the 300,000 Georgia Power accounts

According to ABC 33/40’s report, the intruder reached “limited customer account information through the online customer portal,” not the utilities’ operating systems. The same report puts Georgia Power at about 300,000 customers and Alabama Power at 100,000, which is how the Georgia number in this story is scoped: it is a share of the Southern Company total, not a separate Georgia Power count issued on its own.

WBRC quoted the company directly: “An unauthorized third party accessed certain, limited information about the accounts of approximately 400K customers,” adding that the company took immediate steps to stop the activity once it was detected and has engaged law enforcement Quartz, reporting on Oct. 6, split the same total into 300,000 Georgia Power customers and 100,000 from other Southern Company subsidiaries.

Exposed fields: names, contact details and four SSN digits

Southern Company stated that the data did not include bank account numbers, payment card numbers or driver’s license numbers. CNAW’s coverage repeats that exclusion alongside the list of what was taken, and notes that the company’s investigation found no evidence of ongoing unauthorized access after the activity was stopped.

Four digits of a Social Security number are not enough to open credit by themselves. Paired with a verified name, address, phone number and email, they work as a credibility token: a caller who recites them sounds like a billing department. Georgia Power’s own warning, as relayed in the coverage, points at the likeliest misuse: the utility said it will never threaten immediate disconnection or demand payment over the phone, which is the script a phone scammer holding these details would be tempted to run.

Equifax monitoring and the Federal Trade Commission’s checklist

Southern Company says affected customers are being notified by mail and email, and each is offered one year of complimentary credit monitoring through Equifax. A dedicated assistance line, 1-800-900-6021, was listed by both utilities, according to WEIS Radio’s summary of the WBRC and WSB-TV reports.

The Federal Trade Commission draws a clear line between its two main tools. Its guidance says a credit freeze lasts until the consumer lifts it, requires contacting Equifax, Experian and TransUnion separately, and blocks new accounts entirely, while a fraud alert needs only one bureau, which must tell the other two, and lasts one year at the initial level. Both are free.

The monitoring offer runs for twelve months, but the exposed data does not expire on that schedule, and monitoring only reports on credit activity after the fact rather than preventing a scammer from using the details elsewhere. A name matched to a phone number and four Social Security digits stays valid for years, which is why the FTC’s separate advice on phishing messages matters here: contact the company using verified contact details, never the number or link inside the unexpected message. Anyone who already responded to such a message is pointed to IdentityTheft.gov for a recovery plan matched to what was shared.

Southern Company’s public record on the incident

The public record so far consists of company statements relayed by television and radio stations. No regulator filing was located in the coverage reviewed, and the company’s wording describes an “unauthorized third party” without naming how that party got into the portal or how long the access lasted.

The count itself is the firmest piece of the account, and it is stated the same way in every version: about 300,000 at Georgia Power, about 100,000 at Alabama Power, about 400,000 across Southern Company, all tied to the online customer portal rather than to any payment system. Every outlet reviewed, all drawing on the same Oct. 5 statement, lands on the same 300,000, 100,000 and 400,000 figures, and none of the reports reviewed on Oct. 7 carried a revised number. The unresolved item is the duration of access, which determines whether the 400,000 accounts were swept up in one session or accumulated over weeks.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview

Morning Overview is reader-supported. Some links in our articles are affiliate links, and we may earn a commission at no extra cost to you. As an Amazon Associate I earn from qualifying purchases. Full disclosure.