Were you recently affected by a data breach?

Southern Company Data Breach

Southern Company says an unauthorized third party accessed limited account information of about 400,000 customers of Alabama Power, Georgia Power and Mississippi Power through its online customer portal in September 2026. Notices began in October 2026.

Southern Company
Date of Breach: September 2026
CAU logo

Who was affected:

Clients of Southern Company

Impacted Data:

Names, addresses, phone numbers, email addresses, basic account information, last four digits of Social Security numbers for some customers

Southern Company, the parent of Alabama Power, Georgia Power and Mississippi Power, has confirmed that an unauthorized third party accessed limited account information through its online customer portal. The company says about 400,000 customers were affected, and it began notifying them in October 2026.

Southern Company’s Data Breach Investigation

Southern Company is one of the largest electric utility holding companies in the United States and the parent of regulated utilities including Alabama Power, Georgia Power and Mississippi Power. Customers of those utilities manage their accounts through an online customer portal, where they pay bills, view usage and keep their contact details on file.

According to news reports published around October 5, 2026, Southern Company said it recently detected suspicious activity involving that online customer portal. The company stated that an unauthorized third party accessed certain, limited information about the accounts of approximately 400,000 customers. A recorded customer service message was reported to say the incident happened in September.

Press coverage of the notice indicates that roughly 100,000 of the affected accounts belong to Alabama Power customers, with the rest spread across the other Southern Company utilities. Southern Company has said it took immediate steps to stop the activity once it was detected and that it has engaged law enforcement. Alabama Power has said that so far there is no evidence of ongoing unauthorized access.

Affected customers are being notified directly by U.S. mail and email using the contact information they previously gave the company. The company said it is offering them a free year of credit monitoring and identity theft restoration services. Southern Company has not publicly described how the third party gained access to the portal, and it has not said whether the activity involved stolen login credentials, a software flaw or another method.

The information involved is described in the company’s customer communications as limited, but it still matters. According to those communications, the party behind the incident may have accessed customers’ names, addresses, phone numbers and email addresses, along with basic account information such as the last four digits of some customers’ Social Security numbers. Alabama Power said the account information did not include bank account numbers, payment card numbers or driver’s license numbers.

Even limited data can be useful to criminals. A name, address, phone number and email address tied to a specific electric utility account gives a scammer enough material to write a convincing message that appears to come from the power company, for example a warning about an overdue bill or a threatened disconnection. Utility impersonation scams are already common, and a message that cites real account details is far more likely to be believed. Partial Social Security numbers can also help someone pass weak identity checks when combined with other leaked data.

Utilities hold records for very large populations, including people who have moved, closed accounts or switched to different service addresses. A breach involving a customer portal can therefore reach well beyond current account holders, and the people affected may live across several states. Companies that collect this kind of information are expected to secure it and to monitor their login systems for the kind of automated or unauthorized access that can go unnoticed for days or weeks.

Online customer portals are a common point of attack for large consumer-facing companies because they sit on the public internet, hold data on millions of accounts, and are protected mainly by usernames and passwords. Attackers frequently try login details leaked in unrelated breaches against portals like these, a technique known as credential stuffing, and they can query many accounts quickly if the system does not limit automated activity. Southern Company has not said that this is what happened here, and this page does not claim it, but it is one reason security experts urge customers to use a unique password for every account.

If you receive a notice from Southern Company, Alabama Power, Georgia Power or Mississippi Power, read it carefully and keep a copy. The notice is the best source of information about whether your own account was involved and how to enroll in the credit monitoring being offered. If you did not receive a notice, you may still wish to be careful with any unexpected billing or disconnection messages, since scammers often take advantage of news coverage of an incident to send fake alerts.

When Did This Breach Occur?

Southern Company has not published a precise date range. A recorded customer service message was reported to say the incident happened in September 2026, and the company’s notices and public statements began appearing around October 5, 2026. Southern Company said it detected the suspicious portal activity recently and moved to stop it.

What Information Was Breached?

According to the company’s customer communications, the information may include names, addresses, phone numbers, email addresses and basic account information, such as the last four digits of some customers’ Social Security numbers. Alabama Power said bank account numbers, payment card numbers and driver’s license numbers were not part of the account information involved.

What You Can Do

If you are a Southern Company, Alabama Power, Georgia Power or Mississippi Power customer, consider these steps:

  • Read any notice you receive by mail or email and enroll in the free credit monitoring and identity theft restoration services offered.
  • Be cautious with calls, texts or emails about your power bill, especially any that threaten disconnection or demand immediate payment, and confirm through the number printed on your official bill.
  • Change your online account password, and do not reuse it on other sites.
  • Check your credit reports for free at annualcreditreport.com, and consider a fraud alert or credit freeze with Equifax, Experian and TransUnion.
  • Report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.

File a Data Breach Lawsuit Against Southern Company

If you are a Southern Company customer and received a notice about this incident, or believe your information was exposed, you may have legal options. Utilities are expected to safeguard the personal information customers share with them, and a class action can help hold a company accountable when it fails to do so.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 7, 2026 (date practice learned of the incident)
Date of Breach: Not yet disclosed
Date of Breach: December 30, 2025 to June 7, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.