Origin Energy has confirmed a data breach involving unauthorised access to customer information.

The Australian energy provider is investigating how many people were affected and is contacting confirmed victims directly. Origin Energy serves around 4.8 million customers across its electricity, natural gas and broadband businesses.

Customer details potentially exposed

Origin said the incident may have exposed personally identifiable information belonging to customers.

The potentially affected data includes:

  • Full names
  • Physical addresses
  • Dates of birth
  • Phone numbers
  • Account information
  • The last four digits of payment cards
  • The last three digits of bank account numbers

The company stressed that the exposed financial information is incomplete. According to Origin, the partial details cannot be used on their own to take over customer accounts or make unauthorised bank charges.

Chief executive Frank Calabria apologised to customers and said the company is taking steps to prevent further unauthorised access.

Origin contacts affected customers

Origin initially announced an investigation into a potential security incident. A later update confirmed the Origin Energy data breach.

The company said it will notify impacted customers individually and offer support through a dedicated portal and related resources.

It has also reported the incident to the Australian Federal Police, the Australian Cyber Security Centre and the Office of the Australian Information Commissioner. Origin said it will continue to cooperate with relevant agencies during the investigation.

Origin Energy is Australia’s largest energy retailer. It is listed on the Australian Securities Exchange, reports annual revenue of about $8.5 billion and owns a 20% stake in UK renewable energy retailer Octopus.

Threat actor claims to hold data for 2 million customers

Before Origin released its second statement, a person identifying as “John Doe” reportedly contacted local media and claimed responsibility for the breach.

The threat actor alleged that they held the personal data of two million Origin customers. They also claimed to have contacted security teams, customer support staff and board executives without receiving a response.

The individual reportedly created a website threatening to publish the stolen data within two weeks unless Origin made contact through Signal to negotiate.

Origin has not confirmed the attacker’s claims about the number of records stolen. The investigation remains ongoing.


0 responses to “Origin Energy Data Breach Exposes Customer Information”