Southern Company recently disclosed a data breach affecting approximately 400,000 customer accounts. The breach involved unauthorized access to utility account information through the company’s online customer portal.
Details of the Breach
The Atlanta-headquartered Southern Company, which provides services to over 9 million customers, reported that the breach primarily impacted its electric subsidiaries: Georgia Power, Alabama Power, and Mississippi Power. Of the affected accounts, nearly 300,000 belong to Georgia Power customers, while around 100,000 are from Alabama Power.
Although Mississippi Power was mentioned in the company’s public notice, specific data regarding its affected customers has not been disclosed. The company emphasized that the unauthorized access was limited to certain customer information.
Information Compromised
According to Southern Company’s statement, the data accessed includes customer names, mailing addresses, phone numbers, email addresses, and the last four digits of Social Security Numbers, along with other basic account details. Importantly, no financial information such as bank account or credit card numbers was compromised.
Southern Company is working with law enforcement to address this incident and has taken measures to halt the unauthorized activity.
Response and Next Steps
The company has not provided details on the breach’s timing or how the attackers gained access. Affected customers are being informed via mail and email, with offers of one year of free credit monitoring as a precautionary measure.
This incident highlights the ongoing challenges utility companies face in securing customer data against cyber threats. Southern Company’s swift response underscores the importance of maintaining customer trust and safeguarding sensitive information.
In the wake of this breach, utility companies may need to reassess and enhance their cybersecurity measures to prevent future incidents.
