BIRMINGHAM, Ala. — About 100,000 Alabama Power customer accounts were affected by unauthorized access to its parent company’s online customer portal, an incident disclosed Monday as national data show thousands of information compromises each year and security officials warn artificial intelligence could accelerate cyberattacks.
Southern Company said an unauthorized third party accessed limited information associated with approximately 400,000 customer accounts, including about 100,000 Alabama Power customers and 300,000 Georgia Power customers.
The information may have included names, addresses, phone numbers, email addresses, the last four digits of Social Security numbers and other basic account details, according to the company. Bank account numbers, payment card numbers and driver’s license numbers were not included in the affected information, it said.
Southern Company said it took immediate steps to stop the activity, contacted law enforcement and investigated. It said the investigation found no evidence of ongoing unauthorized access.
“We have conducted a thorough investigation, and we have not identified any evidence of ongoing unauthorized access,” the company said in a statement published by WBRC.
Affected customers are being notified by mail and email and offered one year of free credit monitoring through Equifax. The affected Alabama accounts represent roughly one in 16 of Alabama Power’s approximately 1.6 million customer accounts.
The company statement did not identify the intruders, explain how they gained access or provide precise dates for the intrusion and its discovery. The available disclosures do not establish that artificial intelligence was used or that the incident was connected to a foreign government.
The Alabama Power incident comes amid a sustained national pattern of compromised personal information.
The nonprofit Identity Theft Resource Center recorded 1,803 data compromises during the first six months of 2026, up 3.3% from the same period in 2025. That amounts to about 10 recorded compromises a day. Its latest midyear report lists more than 3,000 compromises in each of the previous three full years.
Those figures are not a count of every attempted cyberattack. They track publicly reported compromises entered into the center’s database, including breaches, exposures, leaks and incidents whose type could not be determined. Some result from human or system errors rather than malicious hacking.
Of the 1,803 compromises recorded in the first half of this year, 1,394 were classified as confirmed data breaches. In a separate breakdown by cause, the center attributed 1,256 compromises to cyberattacks.
Utilities accounted for 27 recorded compromises during that period, compared with 30 in the first half of 2025. Financial services, health care and professional services had substantially higher totals, with 387, 281 and 269 compromises, respectively.
The first-half compromises generated approximately 471.2 million victim notices. That does not mean 471.2 million different Americans were affected: One person can receive notices from multiple incidents, and the total includes a large education-platform breach whose U.S.-only victim count remained unconfirmed.
The center also cautions that it counts incidents according to when they enter its database, not necessarily when the underlying intrusion occurred. Its figures remain subject to revision.
There is evidence supporting concerns that artificial intelligence will make cyberattacks easier to conduct, though security officials do not describe the outcome as inevitable defeat for defenders.
Britain’s National Cyber Security Centre concluded in a May 2025 assessment that AI would almost certainly make parts of cyber intrusion operations more effective and efficient, increasing the frequency and intensity of cyber threats through 2027.
The agency said attackers were already using AI to assist with researching targets, identifying software vulnerabilities, developing basic malicious software, manipulating people into granting access and processing stolen information. More widely available AI tools could expand those capabilities to less experienced attackers, it said.
The assessment warned that AI could shorten the time between disclosure of a software vulnerability and attempts to exploit it, putting organizations that fail to install security fixes at greater risk.
But AI can also help system owners and software developers secure their systems, the agency said. It identified a growing divide between organizations able to keep pace with AI-enabled threats and those falling behind, rather than concluding that digital information can no longer be protected.
The assessment addresses threats from both state-linked actors and criminals. Nothing in Southern Company’s published account establishes that the Alabama Power breach was an act of warfare.
Cybersecurity guidance emphasizes reducing risk rather than abandoning online services.
The U.S. Cybersecurity and Infrastructure Security Agency recommends strong, unique passwords, password managers, multifactor authentication and vigilance against phishing messages that seek personal information or encourage recipients to open harmful attachments.
Those measures help protect access to individual accounts. They do not substitute for security safeguards at companies holding customer information; the Identity Theft Resource Center separately recommends that businesses restrict access to sensitive data, review access rights and maintain security updates.
For people receiving breach notices, the center recommends verifying the notification through the organization’s official website rather than following an unexpected email link, enrolling in offered monitoring and watching for follow-up scams.
It also recommends credit freezes to help prevent criminals from opening new credit accounts using stolen information. A freeze is free and does not affect a consumer’s credit score, according to the center.
Southern Company said it is continuing to monitor its systems around the clock while notifying affected customers.

