LiMP VPN
← All news

Southern Company Breach Hits 400,000 Power Customers

Southern Company Breach Hits 400,000 Power Customers

In short: Southern Company, the parent of Georgia Power and Alabama Power, disclosed a breach of its online customer portal. Attackers accessed data from roughly 400,000 accounts — about 300,000 Georgia Power customers and 100,000 Alabama Power customers, plus an unspecified number of Mississippi Power customers. Exposed data includes names, addresses, phone numbers, emails, and the last four digits of Social Security numbers or tax IDs for business accounts. Bank account numbers, card numbers, and driver's license numbers were not involved, the company said.

What happened

On October 5, 2026, Southern Company reported detecting suspicious activity in its customer web portal: an unauthorized party gained access to a limited set of account data. The company says the incident began in September, with public notifications following in October. It says it has cut off the access, notified law enforcement, and found no evidence of continued unauthorized activity as of disclosure.

Southern Company's subsidiaries serve millions of households across the southeastern US, and a breach of this scale is another sign that utilities and infrastructure providers are becoming as attractive a target as banks and retailers. If you want to check whether your own data has already surfaced in a known leak, see our guide on how to check for a personal data leak.

What data is at risk

The exposed set includes names, mailing addresses, phone numbers, emails, and the last four digits of Social Security numbers (or a tax ID for business accounts). That is enough for classic social-engineering attacks: calls and emails impersonating the company, attempts to reset a password through support, or phishing texts about a fake "electricity bill." Full card numbers, bank details, and driver's license numbers were not affected, according to Southern Company — that lowers the risk of direct financial fraud but doesn't remove the risk of identity theft.

What the company did

Southern Company is notifying all affected customers and offering one year of free credit monitoring and identity-restoration services. The investigation is ongoing, and the exact entry point into the portal hasn't been disclosed as of publication. Lawyers in the US have already begun gathering material for class-action claims — for US customers, that means it's worth reading official notices carefully and avoiding links in emails that look similar but don't come from the company's real domain.

What to do if you could be affected

  • Turn on credit monitoring or a credit freeze if that service is available in your jurisdiction.
  • Don't click links in emails or texts "from the power company" — go to the provider's site directly by typing the address yourself.
  • Use a unique password for your utility portal and a password manager — see our guide on how to choose a secure password manager.
  • Turn on two-factor authentication wherever it's offered.

What this means if you're not a US customer

This breach has no direct link to users outside the US — it affects customers of specific American utilities. But the underlying pattern is universal: the more services hold a piece of your identifying information, the higher the combined odds that at least one of them eventually gets breached. It's also worth cutting network-level risk: on open Wi-Fi in a café, hotel, or airport, traffic can be intercepted or tampered with without an encrypted tunnel. LiMP VPN encrypts your connection and hides your real IP address under a no-logs policy on Android, Windows, and Chrome; see plans on the pricing page.

Sources