Southern Company, the parent of Alabama Power, Georgia Power and Mississippi Power, has confirmed that an unauthorized third party accessed limited account information through its online customer portal. The company says about 400,000 customers were affected, and it began notifying them in October 2026.
Southern Company’s Data Breach Investigation
Southern Company is one of the largest electric utility holding companies in the United States and the parent of regulated utilities including Alabama Power, Georgia Power and Mississippi Power. Customers of those utilities manage their accounts through an online customer portal, where they pay bills, view usage and keep their contact details on file.
According to news reports published around October 5, 2026, Southern Company said it recently detected suspicious activity involving that online customer portal. The company stated that an unauthorized third party accessed certain, limited information about the accounts of approximately 400,000 customers. A recorded customer service message was reported to say the incident happened in September.
Press coverage of the notice indicates that roughly 100,000 of the affected accounts belong to Alabama Power customers, with the rest spread across the other Southern Company utilities. Southern Company has said it took immediate steps to stop the activity once it was detected and that it has engaged law enforcement. Alabama Power has said that so far there is no evidence of ongoing unauthorized access.
Affected customers are being notified directly by U.S. mail and email using the contact information they previously gave the company. The company said it is offering them a free year of credit monitoring and identity theft restoration services. Southern Company has not publicly described how the third party gained access to the portal, and it has not said whether the activity involved stolen login credentials, a software flaw or another method.
The information involved is described in the company’s customer communications as limited, but it still matters. According to those communications, the party behind the incident may have accessed customers’ names, addresses, phone numbers and email addresses, along with basic account information such as the last four digits of some customers’ Social Security numbers. Alabama Power said the account information did not include bank account numbers, payment card numbers or driver’s license numbers.
Even limited data can be useful to criminals. A name, address, phone number and email address tied to a specific electric utility account gives a scammer enough material to write a convincing message that appears to come from the power company, for example a warning about an overdue bill or a threatened disconnection. Utility impersonation scams are already common, and a message that cites real account details is far more likely to be believed. Partial Social Security numbers can also help someone pass weak identity checks when combined with other leaked data.
Utilities hold records for very large populations, including people who have moved, closed accounts or switched to different service addresses. A breach involving a customer portal can therefore reach well beyond current account holders, and the people affected may live across several states. Companies that collect this kind of information are expected to secure it and to monitor their login systems for the kind of automated or unauthorized access that can go unnoticed for days or weeks.
Online customer portals are a common point of attack for large consumer-facing companies because they sit on the public internet, hold data on millions of accounts, and are protected mainly by usernames and passwords. Attackers frequently try login details leaked in unrelated breaches against portals like these, a technique known as credential stuffing, and they can query many accounts quickly if the system does not limit automated activity. Southern Company has not said that this is what happened here, and this page does not claim it, but it is one reason security experts urge customers to use a unique password for every account.
If you receive a notice from Southern Company, Alabama Power, Georgia Power or Mississippi Power, read it carefully and keep a copy. The notice is the best source of information about whether your own account was involved and how to enroll in the credit monitoring being offered. If you did not receive a notice, you may still wish to be careful with any unexpected billing or disconnection messages, since scammers often take advantage of news coverage of an incident to send fake alerts.
When Did This Breach Occur?
Southern Company has not published a precise date range. A recorded customer service message was reported to say the incident happened in September 2026, and the company’s notices and public statements began appearing around October 5, 2026. Southern Company said it detected the suspicious portal activity recently and moved to stop it.
What Information Was Breached?
According to the company’s customer communications, the information may include names, addresses, phone numbers, email addresses and basic account information, such as the last four digits of some customers’ Social Security numbers. Alabama Power said bank account numbers, payment card numbers and driver’s license numbers were not part of the account information involved.
What You Can Do
If you are a Southern Company, Alabama Power, Georgia Power or Mississippi Power customer, consider these steps:
- Read any notice you receive by mail or email and enroll in the free credit monitoring and identity theft restoration services offered.
- Be cautious with calls, texts or emails about your power bill, especially any that threaten disconnection or demand immediate payment, and confirm through the number printed on your official bill.
- Change your online account password, and do not reuse it on other sites.
- Check your credit reports for free at annualcreditreport.com, and consider a fraud alert or credit freeze with Equifax, Experian and TransUnion.
- Report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.
File a Data Breach Lawsuit Against Southern Company
If you are a Southern Company customer and received a notice about this incident, or believe your information was exposed, you may have legal options. Utilities are expected to safeguard the personal information customers share with them, and a class action can help hold a company accountable when it fails to do so.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.