Southern Company breach exposes 400,000 utility accounts

Southern Company breach exposes 400,000 utility accounts

Southern Company is notifying roughly 400,000 customers that an unauthorized third party accessed their utility account information through the company's online customer portal.

The Atlanta-based energy holding company operates electric utilities in three US states and natural gas distribution businesses in four, serving more than 9 million customers in total. Its electric subsidiaries are Georgia Power, Alabama Power and Mississippi Power.

Most affected accounts belong to Georgia Power

Georgia Power customers account for the largest share of the incident, with about 300,000 accounts affected. Southern Company says another 100,000 or so belong to Alabama Power, which has 1.6 million accounts in total.

Mississippi Power also appears in the company's public notice, but Southern Company has not said how many of its customers are affected.

"An unauthorized third party accessed certain, limited information about the accounts of approximately 400K customers. Upon detection, we took immediate steps to stop the activity and have engaged law enforcement," the company said in a statement sent to the media.

What data was exposed

The public notice lists the categories of information involved. "Based on our investigation to date, the limited customer account information that the unauthorized party gained access to includes the customer's name, mailing address, phone number, email, or the last 4 digits of their Social Security Number, and other basic account details," the notice reads.

In the US, the Social Security Number is a national identifier used for taxes, credit checks and many official processes. Even partial numbers are valuable to fraudsters, because the last four digits are often used to verify identity with banks, phone carriers and service providers.

According to the utility, the attacker did not access bank account numbers, payment card numbers or driver's license numbers.

Key questions remain open

Southern Company has not said when the intrusion took place. It has also not explained how the attacker got into the customer portal, so it is unclear whether stolen credentials, a software flaw or some other weakness was involved.

Affected customers are being contacted by mail and email. The company is offering them a year of free credit monitoring, a service that alerts people to changes in their credit file, such as new accounts opened in their name.

Our Take

At first glance, this looks like a lower-severity breach. No payment data, no bank details and no full government ID numbers were taken. But the mix of data that was exposed should not be dismissed. Names, home addresses, phone numbers, email addresses and partial Social Security Numbers, together with account details from a trusted provider, are useful material for targeted phishing and social engineering.

Utility customers are a good target for this kind of scam. People expect to hear from their power company about bills, outages and payment problems, and messages that threaten disconnection create urgency. A fraudster who can quote a real account detail and the last four digits of an SSN will sound much more convincing. Affected customers should be careful with unexpected calls, texts or emails that claim to come from Georgia Power, Alabama Power or Mississippi Power, especially those asking for payments.

The incident also fits a pattern we have covered recently, where partial or seemingly harmless identifiers end up in attackers' hands. Examples include the Frontline Education breach, which exposed school staff SSNs, and the much larger Denmark CPR register incident. Customer-facing portals are a common entry point in these cases, and retailers have seen similar problems, as the recent ASOS cyberattack showed.

It is worth watching whether Southern Company discloses how the portal was accessed and when the activity started. It is also worth watching whether a figure for Mississippi Power customers appears in later notifications. Since the company operates critical energy infrastructure, any sign that the intrusion reached beyond customer-facing systems would change the picture considerably. For now, nothing in the company's statements suggests that.