Business

Georgia Power data breach hits 300,000 customers

Utility says hackers exposed addresses, phone numbers and other data, but no bank or credit card information.
(AJC | Source: Pexels)
(AJC | Source: Pexels)
Kristi E. Swartz
48 minutes ago

Hackers hit Georgia Power’s online customer portal last week, exposing information of hundreds of thousands of customers and fueling the debate over online security in a digital economy.

Georgia Power said Monday it was in the process of telling roughly 300,000 of its 2.8 million customers that an “unauthorized party” gained access to “limited” information. The electric company has notified customers by email and by the U.S. Postal Service.

About another 100,000 customers at Georgia Power’s sister utilities in Alabama and Mississippi also were affected. All three are owned by energy giant Southern Co.

“We understand the trust our customers place in us and remain committed to protecting their information,” Georgia Power spokesperson Jacob Hawkins said in a statement emailed to The Atlanta Journal-Constitution.

Georgia Power discovered the data breach through its ongoing monitoring, the company’s email to affected customers said. The hackers gained access to customer contact information including names, addresses, phone numbers, email addresses, other so-called basic account details and the last four digits of their Social Security numbers.

Customers’ bank account numbers, payment card numbers and driver’s license numbers were not stolen, the company said.

Georgia Power said it took steps to stop the cyberattack, contacted law enforcement and did its own investigation to make sure the hackers were no longer accessing any information.

The utility also spoke with its regulator on Friday afternoon.

“The first thing I asked was, with the affected customers, what are they offering them to help,” Georgia Public Service Commission Chairperson Jason Shaw said in an interview with the AJC.

The PSC requires the utilities it regulates to have proper security plans in place to stave off cyberattacks, Shaw said. He is aware it is commonplace for public utilities and other corporations to be targets of cyberattacks. That one was successful is an anomaly, he said.

“Everybody is subject to these threats all the time,” he said. “It’s a constant thing.”

Georgia Power set up a dedicated customer line for questions and is providing affected customers free credit monitoring through Equifax.

Shaw said the PSC is staying on top of the issue and asking for continual updates from Georgia Power.

“We’re watching this closely,” he said.

That the electric company did not tell the public about the cyberattack and data breach until Monday has concerned consumer advocates. The AJC learned about the data breach through an affected customer.

“The most important thing at a time like this is transparency,” said Liz Coyle, executive director of Georgia Watch, a consumer watchdog group. Coyle said the utility should have alerted all customers last Friday, giving everyone the opportunity to change their online passwords and check their bank accounts and credit scores.

There is no uniform policy on how states should disclose data breaches. Some states have a specific process of doing so, and that is typically handled through the attorney general’s office.

In Georgia, companies are required to tell customers whose personal information may have been exposed “in the most expedient time possible and without unreasonable delay.” There is no set deadline, however, and companies are not required to tell any state agency of a data breach.

A spokesperson in Gov. Brian Kemp’s office referred all questions to Georgia Power and the PSC.

For its part, Georgia Power’s first priority was making sure any unauthorized access was stopped, Hawkins said. Then the utility moved as quickly as possible to make sure it had an accurate list of customers and what type of data was exposed, he said.

Cyberattacks are common, and Coyle said the types of scams have not changed. The increased use of AI makes the threat more prevalent, however.

“AI, without question, facilitates cyberattacks and facilitates scams,” she said. “It just makes it that much easier for attackers to target their customers.

Some Chick-fil-A accounts were hacked in July. In May, hackers attacked Canvas, a popular learning platform, exposing data of millions of students from K-12 to the university level.

Both the City of Atlanta and Fulton County have been hit with ransomware cyberattacks.

AJC reporter Mirtha Donastorg contributed to this article.

A note of disclosure

This coverage is supported by a partnership with Green South Foundation and Journalism Funding Partners. You can learn more and support our climate reporting by donating at ajc.com/donate/climate.