Origin Energy, Australia’s largest energy provider, has officially confirmed a data breach caused by an unidentified attacker, compromising customers’ personally identifiable information (PII).
With a customer base of 4.8 million, the company is currently investigating the extent of the breach and will notify affected individuals about potential risks.
As Australia’s premier energy retailer, Origin Energy supplies electricity, natural gas, and broadband internet services to millions nationwide.
Listed on the ASX, Origin boasts annual revenues of $8.5 billion and little-known to many, holds a 20% stake in UK-based renewable energy retailer, Octopus.
On July 22, Origin announced the initiation of an investigation regarding a “potential security incident” that may involve unauthorized access to customer data.
Recent updates from the company, available on their website, indicate that the following types of data may have been exposed:
- Full Name
- Physical Address
- Date of Birth
- Telephone Number
- Account Information
- Last 4 Digits of Credit Card
- Last 3 Digits of Bank Account
Origin reassured customers that the financial information exposed was “incomplete” and could not potentially lead to account takeovers or fraudulent transactions.
Origin’s CEO, Frank Calabria, extended apologies to customers for the exposure of sensitive data and stated that measures are being implemented to prevent further unauthorized access.
The company is directly contacting affected clients and providing support via a dedicated portal and relevant resources.
Authorities including the Australian Federal Police (AFP), the Australian Cyber Security Centre, and the Australian Information Commissioner’s Office have been notified about the incident, and Origin will continue cooperating with these agencies.
Claims of Massive Data Theft by Attackers
As reported by 7 News, an attacker identifying as “John Doe” claimed to have stolen information from 2 million Origin customers before the company issued its second statement.
The hackers asserted that they contacted the security team, customer support, and even board members, but reported receiving no responses.
The hackers have set up a website threatening to leak the stolen data unless Origin engages with them via Signal to negotiate a resolution within two weeks.
Security teams document 54% of successful cyber attacks but warn about the remaining 46% going undetected. Picus’ whitepaper illustrates testing your SIEM and EDR rules using breach simulations to expose unnoticed threats.
Source: www.bleepingcomputer.com




