Origin Energy Confirms Customer Data Breach Affecting Millions
Auf einen Blick
- Origin Energy, Australia's largest energy retailer, confirmed unauthorized access to and disclosure of some customer data, including names, addresses, and partial payment details.
- The breach, affecting millions, was reported after an alleged hacker contacted The Australian.
- CEO Frank Calabria apologized, stating system security is a key priority.
KI-generierte Zusammenfassung
Warum es wichtig ist
Origin Energy, Australia's largest energy retailer with over 4.8 million customers, confirmed a data breach affecting customer names, addresses, dates of birth, contact numbers, account info, and partial payment details. The incident follows similar breaches at other major Australian companies.
Energy company Origin has confirmed there has been unauthorised access to and disclosure of some customers' data.
In a statement released via the ASX, the company said it was still working to understand the total number of affected customers and would contact any customers when it had confirmation.
The company confirmed yesterday it was investigating a "potential" customer data breach.
Origin said affected customer data may include name, address, date of birth, contact phone number and account information, and the last four digits of a credit card or last three digits of a bank account.
The company had previously told customers via email it did "not believe the impacted information includes customer credit card or bank details".
"I'm sorry this has happened. Customers trust Origin with their information, and I apologise for the impact this may cause," chief executive Frank Calabria said in a statement.
"One of our key priorities is taking action to secure our systems and ensure no further unauthorised access."
The incident was first reported at 12:21pm yesterday by The Australian, which had been contacted by an alleged hacker who sent the outlet a sample of 50 customer records containing names, addresses, emails, dates of birth, phone numbers and bill history.
It was only after The Australian sent that information to Origin that the company alerted authorities to a potential security breach. The company then notified the Australian Securities Exchange at 12:42pm.
The statement this afternoon is the first comment made by the company regarding the incident since it confirmed its initial investigation.
The ABC has spoken to a person claiming to be behind the hack, and has been provided with what the person claims is a sample of data taken from a bigger customer list and internal screenshots of Origin computer systems.
The ABC has not been able to confirm with Origin that this data is legitimate.
Analysis of the sample shows it includes the real contact information that had not been publicly released in other major security breaches.
Origin is the country's largest energy retailer with more than 4.8 million customers across its electricity, gas, LPG and internet businesses.
The data breach is believed to be the largest known incident experienced by an Australian energy retailer. A cyber incident in September 2022 resulted in details of hundreds of EnergyAustralia customers being exposed.
They included names, addresses, email addresses, electricity and gas bills, phone numbers, and the first six and last three credit card digits.
Billing delays not connected to breach
Before the data breach was investigated and later confirmed, several Origin Energy customers had reported that there had been delays in receiving their energy bills.
A customer told the ABC that he had assumed the company had been hacked after he did not receive his quarterly bill as usual on July 5.
The man, who is a long-time Origin customer.
He said he had never had his bill arrive later than two to three days after the account period.
A message on his online account states: "A copy of your bill hasn't been sent. We're working on resolving this delay. Thanks for your patience."
Earlier today, a spokesperson for Origin Energy said delayed bills were likely related to impacts from the July price changes and would not be connected to the potential breach it was investigating at the time.
Origin is the latest major Australian company to experience a security breach after Qantas suffered a major hack in 2025 and Optus and Medibank experienced mass breaches in 2022.
Last week, Partnered Health, which operates a network of GP clinics, was targeted in a cyber attack that resulted in sensitive medical records and personal information being stolen.
"Everybody has been on notice," UNSW cybersecurity professor Richard Buckland said.
"That this is [still] happening is just concerning. How seriously does [the Origin] board take security?
"Because they are a power provider, you'd hope they take it seriously."
Professor Buckland said Origin customers needed to be vigilant about calls, texts and emails from scammers claiming to be company representatives now that the hack has been confirmed.
Worauf zu achten ist
KI-Ausblick — Möglichkeiten, keine Fakten
Origin will contact affected customers.
Sehr wahrscheinlich · Innerhalb von Wochen
Origin will take action to secure its systems.
Sehr wahrscheinlich · Innerhalb von Monaten
Offene Fragen
- What is the total number of affected customers?
- What specific actions will Origin take to secure systems?
- What is the full extent of the compromised data?
