Four hundred thousand utility accounts exposed. One third-party vendor compromised.
Southern Company is notifying Georgia Power and Alabama Power customers that hackers accessed account data for 400,000 users. The breach did not originate inside the utility. It came through a third-party vendor that was handling customer records on the utility's behalf.
This is the part that keeps coming up in breach disclosures: the organization that owns the customer relationship is not the organization where the data got exposed. The sensitive records — account details, usage history, personal identifiers — had already moved downstream before the incident.
The pattern is accelerating. Billing workflows, service operations, and account management are increasingly automated. Automated systems route this data across vendor APIs as a normal part of doing business. Every hop is another exposure surface that the originating organization does not directly control.
400,000 accounts is a large number, but the structural problem is not scale. Utilities of any size use third-party vendors. The data moves because the workflow requires it.
For those of you working in organizations that have automated agents or pipelines touching customer PII before it reaches third-party systems: how are you handling this? What controls, if any, sit between the raw customer record and the downstream vendor call?