Southern Company said an unauthorized party reached account information for a limited group of customers at Georgia Power, Alabama Power and Mississippi Power. SecurityWeek reported on 7 October that about 400,000 customers are being told, and that the access came through the online customer portal. It put roughly 300,000 at Georgia Power and roughly 100,000 at Alabama Power. The company said the data included names, addresses, phone numbers, emails, or the last four digits of a Social Security number. Bank, card and driver's license numbers were not reached.
Much is still open. SecurityWeek said the company has given no date for the intrusion and no method. No count exists for Mississippi Power. The company has not said how many people had each kind of data exposed. It said its review so far shows no sign of continued access. Police are involved and the investigation goes on. Affected customers get a letter or email, plus a year of free credit monitoring from Equifax.
The company calls the group limited, but without knowing how access worked, customers cannot judge the real exposure. For anyone who runs a customer portal, the questions are general: what does it store, what is masked, how is bulk access limited and spotted, and how fast is odd activity caught? Where a portal holds both contact details and partial ID digits, an impersonator can sound more credible.