Southern Company, the parent of Alabama Power, confirmed that an unauthorized third party gained access to limited customer information through the utility’s online portal. The breach affected roughly 100,000 of Alabama Power’s 1.6 million accounts, part of a larger incident that impacted about 400,000 customers across the company’s brands.
What Information Was Exposed
The compromised data includes customer names, addresses, phone numbers, email addresses, and the last four digits of Social Security numbers, along with other basic account details. Southern Company emphasized that bank account numbers, payment‑card numbers and driver’s license numbers were not part of the exposed information.
Company Response
According to the utility, suspicious activity on the online portal was detected recently, and steps were taken immediately to stop the unauthorized access. Law enforcement has been notified, and an internal investigation is underway. The company reports no evidence of ongoing unauthorized access and is continuing to notify affected customers.
As part of its response, Southern Company is offering one year of complimentary credit‑monitoring services through Equifax to anyone whose information was involved in the breach.
What Customers Should Do
Customers whose data was exposed are urged to remain vigilant for unexpected emails, text messages or phone calls that appear to come from Alabama Power or other trusted organizations. Fraudsters can use the stolen details to craft convincing phishing attempts.
Consumers should avoid providing passwords, full Social Security numbers, payment information or other sensitive data in response to unsolicited communications. If a message claims to be from Alabama Power, verify its authenticity using contact information obtained directly from the utility’s official website or billing statements, not the contact details supplied in the suspicious message.
Broader Context
Data breaches of utility companies have become increasingly common as cyber‑criminals target the wealth of personal information held by large service providers. While Southern Company’s swift detection and response are commendable, the incident underscores the importance of robust cybersecurity measures and ongoing vigilance by both providers and consumers.
Alabama residents who receive notification letters or emails from Alabama Power should follow the provided instructions for enrolling in the free credit‑monitoring program and consider placing fraud alerts on their credit reports.
Looking Ahead
Southern Company has pledged to continue its investigation and to keep customers informed of any new developments. The utility also indicated that it will review and strengthen its online security protocols to prevent future incidents.
For additional guidance on protecting personal information after a data breach, consumers can consult resources from the Federal Trade Commission and the Alabama Attorney General’s Office.
Original reporting: The Tuscaloosa Thread — read the source article.