Georgia Power Data Breach: What Happened and Who's Affected

A breach of Georgia Power's online customer portal, part of a wider Southern Company incident, exposed contact details and partial Social Security numbers for roughly 300,000 Georgia customers.

Plant Vogtle, the nuclear power facility co-owned by Georgia Power and operated by Southern Nuclear, a Southern Company subsidiary
Plant Vogtle nuclear facility. Image: Southern Company.

Hackers broke into Georgia Power's online customer portal and accessed personal information belonging to roughly 300,000 of the utility's 2.8 million customers, the company has confirmed, in a breach that also touched about 100,000 customers of sister utilities under parent company Southern Company. The exposed data included names, addresses, phone numbers, email addresses and the last four digits of customers' Social Security numbers — but not full Social Security numbers, bank account or payment card numbers, or driver's license numbers, according to the company's statements to local media.

The short version:

  • What happened: An unauthorized third party accessed Georgia Power's online customer portal, part of a wider incident across Southern Company's footprint.
  • Who's affected: About 300,000 of Georgia Power's roughly 2.8 million customers, plus about 100,000 customers at sister utilities Alabama Power and Mississippi Power — roughly 400,000 accounts total.
  • Data exposed: Names, addresses, phone numbers, email addresses, other basic account details, and the last four digits of Social Security numbers.
  • Not exposed: Full Social Security numbers, bank account numbers, payment card numbers, or driver's license numbers, per the company.
  • Company response: Notifying affected customers by mail and email, offering one year of free credit monitoring through Equifax, and says it found no evidence of ongoing unauthorized access.

What happened

Georgia Power said it "recently detected suspicious activity involving our online customer portal," according to a company statement reported by WSB-TV and other Atlanta-area outlets. The company says an unauthorized third party gained access to limited customer account information through that portal. Georgia Power has not publicly specified the exact date the intrusion began or the date it was first detected, saying only that the activity was identified through its ongoing security monitoring.

The incident is not isolated to Georgia Power. It is part of a broader breach affecting Southern Company, the Atlanta-based energy holding company that also owns Alabama Power and Mississippi Power. Southern Company has said the same unauthorized access affected customer accounts across its utility subsidiaries, with Georgia Power accounting for the largest single share of affected customers.

Georgia Power said it moved to stop the unauthorized activity as soon as it was identified, and that it has since completed an internal investigation. "We have conducted a thorough investigation, and we have not identified any evidence of ongoing unauthorized access," the company said, according to Channel 2 Action News's reporting. The company also says it has notified law enforcement.

What data was exposed

According to Georgia Power's statements and reporting from multiple outlets that reviewed the company's customer notices, the breach exposed a defined set of personal information rather than full financial or government-ID records. The company has repeatedly emphasized what was not taken alongside what was.

ExposedNot exposed
Full nameFull Social Security number
Home addressBank account numbers
Phone numberPayment card numbers
Email addressDriver's license numbers
Last four digits of Social Security numberAccount passwords (per company statements)
Other basic account details—

One outlet's account of the company's notice also referenced the last four digits of business tax identification numbers as potentially exposed for some commercial accounts, though this detail has not been consistently repeated across all reports. Georgia Power has not released a line-by-line technical breakdown of exactly which fields were accessed for which customers, and multiple outlets, including the Atlanta Journal-Constitution, have noted that the company did not specify precisely what information was accessed or exactly when the suspicious activity occurred.

The combination of contact information with a partial Social Security number is still useful to scammers, even without a full nine-digit number. Fraudsters can pair the last four digits of an SSN with a name, address and phone number to make phishing calls, texts or emails sound more convincing, or to pass identity-verification questions at call centers that rely on partial identifiers.

Who is affected

Georgia Power says it is notifying roughly 300,000 of its approximately 2.8 million customers. Reporting on the Southern Company side of the incident puts the remaining affected accounts — around 100,000 — at sister utilities Alabama Power and, according to the AJC's reporting, Mississippi Power as well. Local Alabama outlets, including ABC 33/40, have reported the 100,000 figure as specific to Alabama Power customers; the exact split between Alabama Power and Mississippi Power accounts within that figure has not been independently confirmed and differs slightly between outlets. Combined, Southern Company has said approximately 400,000 customer accounts across its utility footprint were affected.

Not every Georgia Power customer is affected. The company has said it is directly notifying only those whose accounts it has identified as involved, by email and by U.S. Postal Service mail. If you are a Georgia Power customer and have not received a notice, the available reporting does not confirm whether that means your account was not involved or simply that a notice has not yet arrived; see the section below on how to check your status.

How the breach was discovered and disclosed

Georgia Power says it found the suspicious activity through its own ongoing account-security monitoring, rather than through a tip from law enforcement, a researcher or the attackers themselves. The company has not disclosed the exact date of detection beyond characterizing it as recent, and news coverage from October 5 and 6, 2026 described the activity as having been identified "last week" relative to those reports.

Disclosure of the breach to the public followed, rather than preceded, direct notices to some customers. The AJC has reported that it learned of the breach from an affected customer rather than from a company announcement, and consumer advocates quoted in local coverage criticized the pace of public disclosure. Georgia Power's statements to reporters have focused on the steps taken once the activity was detected rather than on a detailed incident timeline.

Southern Company's response

Southern Company and Georgia Power have outlined a standard set of post-breach remediation steps:

  • Took immediate action to stop the unauthorized activity once detected.
  • Contacted law enforcement.
  • Conducted an internal investigation that the company says found no evidence of continuing unauthorized access.
  • Began notifying affected customers directly by email and by U.S. mail.
  • Is offering one year of free credit monitoring through Equifax to affected customers.

A Georgia Power spokesperson, identified in reporting as Jacob Hawkins, said: "We understand the trust our customers place in us and remain committed to protecting their information." Georgia Public Service Commission chairman Jason Shaw, whose body regulates the utility, said of the incident, "We're watching this closely," and has asked the company what it is offering to help affected customers, according to local reporting.

The Georgia Public Service Commission's attention matters here because Georgia Power is a regulated monopoly utility: customers cannot simply switch providers the way they might after a retailer breach, which raises the stakes on how thoroughly the company investigates and how clearly it communicates with regulators and the public going forward. Southern Company has not said whether it expects to face fines, additional regulatory reporting requirements, or litigation as a result of the incident, though a law firm has already begun soliciting affected customers for a possible class action, according to published breach-notice tracking sites.

How to check if you're affected

As of this writing, Georgia Power has not publicized a standalone online lookup tool where customers can enter their account details to check breach status, based on the reporting reviewed for this article. The company's stated notification method is direct outreach: affected customers are being contacted by email and by letter through the U.S. Postal Service. Practical steps if you're a Georgia Power, Alabama Power or Mississippi Power customer:

  • Check the email address and physical mailing address on file with your utility account for a notification letter or email from the company.
  • Do not click links in unsolicited emails or texts claiming to be from Georgia Power about the breach; go directly to georgiapower.com or call the number printed on a past bill if you want to verify an account issue.
  • If you believe you should have received a notice and have not, contact Georgia Power customer service directly through the number on your bill or the official site rather than a number provided in an email or text.
  • Keep any notification letter or email you do receive; it may contain specific instructions or an enrollment code for the free credit monitoring offer.

How to protect yourself

Because the breach exposed contact information alongside a partial Social Security number, the realistic risk for most affected customers is targeted phishing and impersonation scams rather than immediate direct financial fraud. Still, a few concrete steps reduce exposure:

  • Enroll in the free credit monitoring. If you receive a notice from Georgia Power or Southern Company, consider enrolling in the offered year of Equifax credit monitoring; it can flag new accounts opened in your name.
  • Consider a credit freeze. A freeze with each of the three major credit bureaus (Equifax, Experian and TransUnion) is free and blocks new credit from being opened in your name without your explicit action to lift it.
  • Watch for phishing that references this breach. Scammers often use real breach news to craft convincing follow-up scams. Be skeptical of calls, texts or emails that reference the Georgia Power breach and ask you to "verify" your account, Social Security number or payment details.
  • Use unique, strong passwords for your utility account and other accounts, ideally managed with a password manager rather than reused or easily guessed passwords; see our guide to password managers for how they work.
  • Turn on multi-factor authentication wherever your utility or financial accounts offer it. Our comparison of authenticator apps covers the main options if you haven't set one up.
  • Monitor your accounts and credit reports for unfamiliar activity over the coming months, not just the next few weeks, since stolen contact and partial-identifier data can be used well after initial disclosure.

What we don't know yet

Several details remain unconfirmed in public reporting as of this writing. Georgia Power has not disclosed the exact date the intrusion began, nor has it named a suspected attacker or group. The company has not detailed precisely how the unauthorized party gained access to the customer portal. Reporting also varies on the exact breakdown of the roughly 100,000 non-Georgia-Power accounts between Alabama Power and Mississippi Power, and on whether business tax ID numbers were exposed for any commercial accounts. We will update this article if Georgia Power, Southern Company or Alabama Power releases further specifics.

What to do next

If you have an account with Georgia Power, Alabama Power or Mississippi Power, the most useful immediate steps are checking your mail and email for an official notice, enrolling in the free credit monitoring if you're confirmed as affected, and treating any unsolicited message that references this breach with suspicion rather than urgency. A credit freeze costs nothing and can be lifted later if you need to apply for credit. Beyond this specific incident, the broader lesson for consumers is that utility accounts are increasingly attractive targets precisely because they hold enough personal data to support identity-theft-adjacent fraud, even when full financial or Social Security data isn't taken. Utilities, schools and courts have all disclosed similar contact-and-partial-identifier breaches in recent months; our coverage of the ASOS data breach looked at a comparable retailer incident and the notification and monitoring response that followed it. The pattern across these cases is consistent: companies emphasize what wasn't stolen, offer a year of free monitoring, and leave open questions about exact timelines that often get filled in only as litigation or regulatory inquiries proceed.

For now, Georgia Power, Alabama Power and Mississippi Power customers should treat this as an active, unresolved situation rather than a closed incident. The company says there is no evidence of ongoing unauthorized access, but it has not released a full timeline, has not named an attacker, and has not detailed exactly how the portal was compromised. We'll update this article as Southern Company, Georgia Power or state regulators release additional information.

Frequently asked questions

How many Georgia Power customers were affected by the breach?

About 300,000 of Georgia Power's roughly 2.8 million customers were affected, part of a wider Southern Company incident that the company says affected approximately 400,000 customer accounts in total across Georgia Power, Alabama Power and Mississippi Power.

What personal information was exposed in the Georgia Power breach?

Names, addresses, phone numbers, email addresses, other basic account details, and the last four digits of Social Security numbers. Full Social Security numbers, bank account numbers, payment card numbers and driver's license numbers were not exposed, according to the company.

When did the Georgia Power data breach happen?

Georgia Power has not disclosed the exact date the unauthorized access began. The company says it detected the suspicious activity through its own account-security monitoring and began notifying customers and disclosing the incident publicly in early October 2026.

Is Georgia Power offering credit monitoring to affected customers?

Yes. Georgia Power and parent company Southern Company are offering one year of free credit monitoring through Equifax to customers identified as affected by the breach.

How can I find out if my Georgia Power account was affected?

Georgia Power is notifying affected customers directly by email and by U.S. Postal Service mail. The company has not publicized a separate online lookup tool, so if you haven't received a notice, you can contact Georgia Power customer service using the number on your bill to ask about your account status.

Were Alabama Power and Mississippi Power customers also affected?

Yes. Southern Company, the parent of Georgia Power, Alabama Power and Mississippi Power, has said approximately 100,000 additional customer accounts at its sister utilities were affected, in addition to the roughly 300,000 affected Georgia Power customers.

Sources

More on Georgia Power Data Breach →Georgia Powerdata breachSouthern Companycybersecurityutility security
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all