Origin Energy, one of Australia’s largest energy retailers, has confirmed that a data breach exposed customers’ personally identifiable information following unauthorized access by an unknown threat actor. The company serves 4.8 million customers across Australia, providing electricity, natural gas, and broadband internet services, and is currently investigating the full scope of the incident to determine how many clients were affected.
The energy provider, which generates $8.5 billion in annual revenue and is listed on the ASX, initially announced it had launched an investigation into a potential security incident. A subsequent update confirmed that unauthorized access had indeed occurred, compromising several types of customer data.
What Customer Information Was Exposed in the Origin Energy Breach?
According to Origin Energy’s statement, the breach potentially exposed multiple categories of customer information. The compromised data includes full names, physical addresses, dates of birth, phone numbers, and account information. Financial details were also accessed, though in incomplete form: only the last four digits of credit cards and the last three digits of bank accounts were exposed.
The company emphasized that the exposed financial information is incomplete and cannot be used to hijack accounts or make unauthorized charges to customers’ bank accounts. Origin CEO Frank Calabria issued an apology to customers for the exposure of their sensitive data and assured them that steps are being taken to prevent further unauthorized access.
Who Is Behind the Attack on Origin Energy?
Before Origin Energy released its confirmation statement, a threat actor identifying themselves as ‘John Doe’ contacted local media outlet 7news to claim responsibility for the breach. The hacker alleged to be holding data belonging to 2 million Origin customers and complained that attempts to contact security teams, customer support, and board executives went unanswered.
The threat actor has established a dedicated site where they are threatening to leak the stolen data within two weeks unless Origin Energy contacts them via Signal to negotiate. This extortion attempt adds urgency to the company’s response efforts.
How Is Origin Energy Responding to the Incident?
Origin Energy has notified multiple Australian authorities about the breach, including the Australian Federal Police, the Australian Cyber Security Centre, and the Office of the Australian Information Commissioner. The company continues to engage with these agencies as the investigation progresses.
Customers confirmed to be impacted are being contacted directly through individual notifications. Origin has also established a dedicated portal and related resources to provide support to affected clients as they assess their risk and take protective measures.
Source: Bleeping Computer