Cyber & AI intelligence
Wasteland.
Briefs indexed3038
Issues31
Published Mondays07:30 CT
▣ Breach GEORGIA-POWER-CUST 2026-10-07

Georgia Power: Customer Portal Breach Exposes Roughly 400,000 Southern Company Accounts

"Georgia Power has confirmed that an unauthorized third party got into its online customer portal and accessed "certain, limited information" tied to about 400,000 customer accounts. The exposed data includes names…"

Georgia Power has confirmed that an unauthorized third party got into its online customer portal and accessed "certain, limited information" tied to about 400,000 customer accounts. The exposed data includes names, postal addresses, phone numbers, email addresses and the last four digits of Social Security numbers. The headline number depends on scope. About 300,000 of the affected accounts belong to Georgia Power customers. Roughly another 100,000 belong to customers of sister utilities in Alabama and Mississippi, which are also owned by parent company Southern Company (AJC, WSB-TV, Quartz). Reports headlined at "300,000" (AJC, WTVM, CyberNetSec) count only Georgia Power customers. Reports headlined at "400,000" (Quartz, WSB-TV, CBS-linked coverage, Undercode) count the whole Southern Company group. The two figures describe the same incident. The company has not named the attacker, and no group has publicly claimed it.

What Happened

Georgia Power says it spotted "suspicious activity involving our online customer portal" through its ongoing monitoring. The AJC reports the intrusion took place the week before the October 5 to 6, 2026 disclosures. The company says it moved to stop the activity once it was detected, brought in law enforcement, and ran an internal investigation. The AJC reports the utility briefed its regulator, the Georgia Public Service Commission, on the Friday afternoon before the public announcement. PSC Chairperson Jason Shaw told the AJC that his first question was what the utility would offer affected customers.

Sources differ on whether the investigation is finished. WSB-TV and Quartz quote the company as saying it "conducted a thorough investigation" and found no evidence of ongoing unauthorized access. The customer email quoted by CBS News Atlanta says the company is "conducting a thorough investigation," which suggests the work was still under way when notices went out. Every source agrees that Georgia Power does not believe the access is continuing.

Notifications are going out by email and by U.S. mail. Affected customers are being offered one year of free credit monitoring and identity theft restoration through Equifax. WTVM reports that at least one customer almost deleted the real notice because she thought it was a scam.

There is an unconfirmed earlier report. One OTHER-tier source, CyberNetSec, published a September 30 item saying that on September 29 a database of about 400,000 Southern Company customer PII records was allegedly circulating on underground forums. The item credits Bitsight with flagging it and says it contained names, emails and physical addresses. No other source repeats this claim, and Georgia Power's statements do not mention a forum leak. The record count is a close match, but treat any link between that listing and the portal breach as unverified.

What Was Taken

Georgia Power's statement and every news report agree on the same set of exposed fields:

The company says bank account numbers, payment card numbers and driver's license numbers were not accessed. WSB-TV notes that Georgia Power "has not released specifics about exactly what customer information was accessed" beyond these categories. Some fields, such as account numbers or service details, could therefore fall under "basic account details" without being listed individually.

Volume: about 400,000 accounts across Southern Company's utilities, of which about 300,000 are Georgia Power customers. That is a little over 10% of Georgia Power's roughly 2.8 million customers (AJC).

Why It Matters

Ideal material for impersonation fraud. This data set doesn't allow direct financial theft. It does give a fraudster everything needed to pose convincingly as the utility: a confirmed customer relationship, a service address, contact details and the SSN last-four that many call centers use to verify identity. Utility impersonation scams, such as "pay now or we disconnect today," are already common. Georgia Power's own warning that it "will never threaten immediate disconnection or demand payment over the phone" shows it expects this exact follow-on activity.

The breach notice looks like a scam. The WTVM account shows a real problem. A legitimate notice that tells customers to click a link and call a number for free credit monitoring looks just like the phishing it warns about. Expect attackers to copy the notification itself.

Critical infrastructure, but not OT. Georgia Power is a major electric utility, but nothing in the sources suggests the grid or operational technology was involved. Undercode's analysis makes the same point. This is an IT-side customer data compromise. It still adds to regulatory pressure on utilities, and the PSC chair has publicly linked the incident to the security plans the commission requires.

A shared portal makes one weakness affect several utilities. One portal compromise reached customers of three separately regulated utilities. That suggests a shared platform or identity layer across Southern Company subsidiaries.

The Attack Technique

Not disclosed. Georgia Power has not said how the attacker got in, and no threat actor has been identified or has claimed the attack. There is no reporting of ransomware or extortion.

The two CyberNetSec items map the incident to MITRE ATT&CK T1190 (Exploit Public-Facing Application), T1078 (Valid Accounts) and, in the earlier item, T1041 (Exfiltration Over C2 Channel). These are analyst inferences, not confirmed findings. Both pieces say outright that the vector was not disclosed. The plausible paths for a customer-portal compromise of this kind are:

The fields that were exposed (contact data plus SSN last-four, with no payment data) suggest the attacker reached a profile or account-summary layer and not a billing or payments system. This is an inference from the data mix, not a disclosed fact.

What Organizations Should Do

  1. Hunt for enumeration on customer portals and APIs. Look for high-volume, sequential or cross-account object requests from single sessions, IPs or ASNs. Test every account-scoped endpoint for object-level authorization so it returns only the authenticated customer's records.
  2. Harden consumer authentication. Deploy credential-stuffing defenses: breached-password screening, bot management, rate limiting and anomaly-based step-up challenges. Offer phishing-resistant MFA, or at least app-based MFA, and push users toward it.
  3. Retire SSN last-four as a verification factor. It has now been exposed for hundreds of thousands of customers, so call centers and IVR flows should stop treating it as proof of identity. Move to one-time codes sent to verified channels or account-specific PINs.
  4. Minimize what the portal can return. Customer-facing systems rarely need SSN fragments at all. Mask or tokenize sensitive fields so the web tier never holds them.
  5. Design breach notices that can't be mistaken for phishing. Avoid links in notification emails. Point customers to the URL and phone number printed on their bill. Publish the notice text on the official website so customers can check it.
  6. Monitor underground forums for your customer data. If a 400,000-record listing really appeared on forums before public disclosure, as one unverified report claims, external dark-web monitoring would have been an early warning. Utilities and other consumer-facing critical infrastructure operators should include it in detection.

Sources: Georgia Power data breach exposes 400,000 customer accounts | Georgia Power's data breach affects hundreds of thousands | Georgia Power customer data may have been accessed in data breach,... | Georgia Power says hackers accessed information from about 400,000... | Georgia Power data breach exposes information of 300,000 customers | Georgia Power Data Breach Exposes Information of... - CyberNetSec.io | Georgia Power Customer Portal Breach Exposes Data Linked to Nearly... | Southern Company Investigates Data Breach Affecti... - CyberNetSec.io