Georgia Power breach exposes 400,000 customer accounts across two states

· CyberSecurity

TLDR

  • Georgia Power said an unauthorised third party accessed its online customer portal, exposing account information for about 400,000 customers.
  • Of those, 300,000 are Georgia Power customers and 100,000 are Alabama Power customers; both utilities are subsidiaries of Southern Company.
  • Exposed data includes names, addresses, phone numbers, emails and the last four digits of customers' Social Security numbers; no bank account, card or driver's licence data was taken.
  • Georgia Power says it has completed an investigation, found no evidence of continuing unauthorised access, contacted law enforcement, and is offering affected customers free credit monitoring.

Georgia Power said it "recently detected suspicious activity involving our online customer portal" and determined "an unauthorized third party accessed certain, limited information about the accounts of approximately 400K customers."1 The company said 300,000 of the affected accounts belong to Georgia Power customers, with the remaining 100,000 tied to Alabama Power, a sister utility under the same parent, Southern Company.1 The exposed information includes customers' names, addresses, phone numbers, emails and the last four digits of their Social Security numbers; the company has not disclosed further specifics about exactly what was accessed.1

Georgia Power said it immediately moved to stop the unauthorised activity and contacted law enforcement, and that a completed investigation found no evidence that unauthorized access is continuing.1 The company is now notifying affected customers directly and providing free credit-monitoring services, which it says will be through Equifax for one year.2 The breach has not been linked to a specific threat actor or group.

The incident lands amid a broader rise in attacks on utilities: federal officials have repeatedly warned that hackers linked to foreign governments are increasingly targeting critical infrastructure including electric utilities and water systems, and Georgia itself was among several states that reported cyberattacks on water infrastructure last year.1 Data from the Identity Theft Resource Center shows 2026 is already on pace to be one of the worst years on record for breach volume, a trend researchers increasingly link to AI tools lowering the skill bar for attackers.2

Why it matters: a breach at a dual-state utility holding company shows how a single compromised customer portal can expose personal data across multiple subsidiary brands at once, widening the blast radius well beyond what either individual utility's customer base would suggest.

Sources

  1. Georgia Power cyberattack exposed 400,000 customer accounts (WSB-TV)
  2. Georgia Power data breach exposes 400,000 customer accounts (Quartz)