Origin Energy confirms customer data accessed in hack
L'essentiel
- Origin Energy confirmed a hack accessed customer names, addresses, phone numbers, and partial bank data for an unspecified number of its 4.8m Australian accounts.
- The company is investigating with authorities, while experts warn of identity theft risks.
Résumé généré par IA
Pourquoi c'est important
Origin Energy, a major Australian utility provider with 4.8 million customer accounts, confirmed a hack accessed customer data including names, addresses, phone numbers, and partial bank details. This follows other recent high-profile data breaches in Australia, such as Qantas.
Origin Energy customers’ addresses, phone numbers and partial bank account data have been accessed in a hack, the company has confirmed.
The firm has 4.8m customer accounts in Australia, providing electricity, fossil gas, LPG and internet services to homes and businesses.
Origin has yet to confirm which, and how many, customers had been affected. In a statement to the ASX on Thursday, it said it would tell customers once it confirmed whether they had been affected.
A person claiming to be the hacker has reportedly contacted media outlets with unverified claims that 2 million customers’ details were accessed.
Origin said data may include customers’ names, addresses, dates of birth, phone numbers and Origin account information, as well as the last four digits of a credit card, or the last three digits of a bank account.
The company said incomplete credit card or bank account information could not be used to make purchases or access accounts.
Origin first revealed the hack in a statement yesterday, saying it believed credit card or bank details had not been accessed. The company has not detailed how the hack occurred.
Origin’s chief executive, Frank Calabria, said the company was securing its systems and ensuring there was no further unauthorised access, working with independent cyber experts and authorities.
“I’m sorry this has happened,” Calabria said.
“Customers trust Origin with their information, and I apologise for the impact this may cause.”
Experts have warned customers could be vulnerable if the data is leaked and used for identity theft, or by scammers tricking people into believing they are representatives of real businesses.
Rumpa Dasgupta, a lecturer in cybersecurity at La Trobe University, said personalised records could be misused for physical robberies.
“In the wrong hands, this information could be exploited not only for highly targeted phishing campaigns but also to support physical crimes such as burglary by identifying vulnerable properties,” Dasgupta said.
Origin said the Australian Cyber Security Centre, the Australian federal police and the Office of the Australian Information Commissioner (OIAC) were all investigating.
The National Office of Cyber Security is leading the government’s response.
The Australian reported it was first contacted by a person claiming to have hacked Origin on Tuesday, after which the newspaper alerted Origin, which made a statement on Wednesday.
An Origin spokesperson said the company had moved immediately to update the ASX as soon as it was aware of a potential incident.
The OIAC reported it received 1,205 data breach notifications in 2025, of which 716 were related to malicious or criminal activity.
Among the hacks was a leak of 5 million Qantas customers’ information in October, which prompted warnings scammers could cold call leaked phone numbers.
The federal privacy commissioner last week found Qantas did not make any omissions or failings in breach of the Privacy Act, in relation to the hack. The Australian federal police are investigating.
Questions ouvertes
- Which and how many customers are affected?
- How did the hack occur?
- What is the hacker's identity and motive?






