DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

Southern Company Confirms Data Breach Affecting 400,000 Customers

Southern Company confirmed this week that an intruder reached its online customer portal and accessed the accounts of about 400,000 electricity customers, taking names, email addresses, and fragments of Social Security numbers. I run AliasFleet: a per-service email alias gives every account its own address, so a fake email from your power company fails one test it cannot pass. Keep that test in mind, because this stolen file is a ready-made scam kit.

What the company says happened

The disclosure landed in customer inboxes and on local news stations around October 5, roughly a month after the incident itself. The facts, from the company's statements and the notifications:

Detail What the company said
Who Southern Company, parent of Alabama Power, Georgia Power, and Mississippi Power
What Unauthorized third-party access to "certain, limited information" through the online customer portal
How many Approximately 400,000 customer accounts (statement to WSFA)
Split About 100,000 Alabama Power and 300,000 Georgia Power accounts, per ClassAction.org's lawsuit page, which cites BeyondMachines reporting
When it happened In September 2026, per a recorded customer-service message
When it was disclosed Customer notices began around October 5, 2026
Current status Company says no evidence of ongoing unauthorized access; law enforcement engaged

"Southern Company recently detected suspicious activity involving our online customer portal. An unauthorized third party accessed certain, limited information about the accounts of approximately 400K customers." (Southern Company statement, via CNAW 2 News)

Georgia Power's breach-notification email to customers, as quoted in CBS News Atlanta's reporting

What was taken, and what was not

The customer communications itemize the exposed fields: names, addresses, phone numbers, email addresses, and the last four digits of some customers' Social Security numbers. The company says bank account numbers, payment card numbers, and driver's license numbers were not part of it. Affected customers are getting a year of free credit monitoring and identity theft restoration through Equifax, and notifications are going out by US mail and email.

So the password and payment details stayed home. That sounds reassuring until you think about what the taken fields buy a scammer.

Why this file is a scam kit

The disconnection-threat scam is one of the oldest email tricks in America. Someone posing as your power company warns that your lights go off today unless you pay now, usually to a prepaid card or a money app. Georgia Power's own breach notification admits the company is worried about exactly this, because it printed the tell in the same email:

"As a reminder, we always encourage our customers to be cautious and to beware of individuals claiming to be a Georgia Power representative. We will never threaten immediate disconnection or demand payment over the phone. If you suspect someone is pretending to be a Georgia Power employee, hang up or don't reply, and call us directly at the number on your bill or our website." (Georgia Power customer email, via Bitcomme)

Now pair that warning with the stolen fields. A fake disconnection email that opens with your real name, your real address, and enough account-adjacent detail to sound like it came from inside the portal is a different animal from the usual spray-and-pray version. The SSN fragments are the quiet multiplier: four digits plus a name and address is often enough to pass the weak identity checks that stand between a scammer and account changes. Nobody needs your card number to scare you into handing over payment yourself.


The attackers hold names, addresses, phone numbers, and emails tied to real utility accounts. Any "your power will be disconnected today" message citing your name or address should be treated as hostile until you verify it yourself. Do not pay through a link in the message. Ever.

Georgia Power keeps a standing fraud protection page listing the real sender addresses for billing mail (G2georgiapps@southernco.com) and outage mail (do-not-reply@georgiapower.com). Worth bookmarking now, not when the fake arrives.

If you are one of the 400,000

Work from the notice first. If you received one by mail or email, read it carefully and keep a copy; it is the only source that says whether your account was in the set, and it carries the Equifax enrollment details. Then:

  1. Enroll in the free credit monitoring. It is a year of Equifax monitoring plus identity restoration, and there is no reason to leave it on the table.
  2. Change your portal password, and make it unique. The company has not said how the intruder got in, and a reused password on a public portal is the most common open door there is.
  3. Route every bill message through the official channel. Type the address yourself or use the number on your bill. The company's own guidance: a real Georgia Power email will never threaten immediate disconnection or demand payment details by phone.
  4. Check your credit reports at annualcreditreport.com and consider a fraud alert or freeze. The breach-response guide walks through this in order.
  5. Report suspected identity theft to the FTC at identitytheft.gov, which the company-watch sources point to for incidents like this.
  6. Check whether your email is already circulating from another leak at Have I Been Pwned. Portal intrusions often start with credentials stolen elsewhere, and knowing your address is in the wild changes how seriously you treat every login prompt.

The check a fake email cannot pass

Inspection advice breaks down in exactly this scenario. You can tell people to hover over links and check sender addresses, and you should, but the fake is about to arrive quoting their real name and address. Inspection asks a nervous customer to spot a flaw in a message engineered to have none.

A per-service alias changes the question. If the address Georgia Power holds exists only for Georgia Power, then a "disconnection notice" landing on the alias you created for your streaming service is fake by definition. No hovering, no sender-address forensics, no judgment call. The address itself is the verdict. And when the fakes keep coming, you pause that alias: the whole phishing channel dies while your real inbox stays clean.

That is the same leak-tracing mechanism that names a breached company the moment its alias surfaces in a dump, turned against phishing instead of leaks. Utilities are exactly the services where it pays off: you will never switch power companies the way you switch apps, so the alias lives quietly for years and the verification comes free every time. This is what an email alias is, and the set-up guide takes about two minutes.

What Southern Company has not said

The company has not said how the intruder got into the portal. No stolen credentials, no software flaw, no insider angle has been named, and there is no precise incident date beyond September. There is no word on whether any of the 400,000 files has been misused so far, and no attacker has been named. The roughly 100,000 and 300,000 per-utility figures come from BeyondMachines reporting rather than the company's own statement, and the possible business tax ID fragments sit in that same third-party column. Watch the company's own channels for updates, and treat everything else as provisional.

Top comments (0)