Read as article
Southern Company Breach Exposes 400,000 Customer Accounts
By @sharedot · · 8 pages
- Cybersecurity
- Data Breach
- Southern Company
An unauthorized third party accessed Southern Company utility accounts at Georgia Power and Alabama Power, exposing data on roughly 400,000 customers.
What happened: a third party got into the utility portal
Southern Company, the Atlanta-based energy holding company whose subsidiaries serve electric and natural gas customers across six states, reported a data breach in which an unauthorized third party accessed information about the utility accounts of customers at Georgia Power, Alabama Power and Mississippi Power. A company statement provided to WSFA says approximately 400,000 customer accounts were accessed. The exposed data includes names, addresses, phone numbers, email addresses and the last four digits of Social Security numbers, plus other basic account details. The company says bank account information, payment card numbers and driver's license numbers were not involved.
Why it's surprising: the warning email looked like a scam
The breach notice itself became part of the story. A Georgia Power customer told WTVM she almost deleted the company's email warning that her information was exposed, because it followed the classic phishing pattern: 'data breach, name, phone number, email address, last four of my Social Security. But we will sign you up for free credit monitoring, call this number, click on this link. And I stopped and I'm like, that's a scam.' According to WTVM, she said the incident has shaken her trust in the company: 'If you're going to put all my information in this little box to keep it safe, it's your job to guard that little box.'
The evidence: what each affected utility has confirmed
Georgia Power confirmed to WTVM that an unauthorized third party accessed its online customer portal, exposing limited information for about 300,000 customers. Georgia Power spokesperson Tiffany Anthony said in a statement that the company caught the activity, acted immediately, engaged law enforcement, and found no evidence of ongoing unauthorized access.
The stakes: partial SSNs and the phishing window
Director Amanda Senn told WSFA that 'everyone is exposed to a data breach, it's not if but when,' and cautioned against storing credit card, routing and checking account information online, noting that bots can reuse a password stolen from one site to log in to another. WSFA reports the breach affected more than 100,000 customers.
The fallout: a class action investigation is underway
Attorneys working with classaction.org have opened an investigation into whether a class action lawsuit can be filed over the breach, and are recruiting affected customers — including anyone who received a notice or believes their data was exposed — to hear from potential plaintiffs. According to classaction.org, a successful case could recover compensation for loss of privacy, lost time and out-of-pocket costs, and could force Southern Company to strengthen how it protects customer information. The investigation costs nothing to join and carries no obligation to act.
What comes next: notices, credit monitoring, and unanswered questions
Georgia Power says it is notifying all affected customers by email and mail, and is offering one year of free credit monitoring through Equifax. Customers who have not received a notice can contact the company at 800-900-6021, Monday through Friday from 7 a.m. to 7 p.m., to confirm whether their information was involved. Georgia Power declined an on-camera interview with WTVM, and the investigation is ongoing — classaction.org reports that affected customers will receive notices by mail and/or email as they are identified.