Origin Energy data breach exposes 900,000 customers
Origin Energy says personal details and partial payment numbers of about 900,000 current and former customers were accessed in a cyber intrusion detected in July.
Origin Energy has confirmed a cyber intrusion that exposed personal and partial financial data for about 900,000 current and former customers. The company began investigating a potential security incident in early July and says new information on July 22 confirmed unauthorized access.
The exposed information includes customer names, dates of birth, phone numbers, postal addresses, account details and partial payment card or bank account numbers. Origin is treating the incident as a criminal matter and has notified relevant authorities.
An individual claiming responsibility contacted Origin and claimed to have obtained data for 2 million customers and demanded a ransom, later asserting an agreement had been reached and no data would be released. Origin has not confirmed any agreement or whether a ransom was offered or paid.
Frank Calabria, Origin’s chief executive, stated the matter is under investigation and that the company is constrained in what it can share while authorities pursue the case. Origin also warned that even if the stolen data is not made public, other criminals could use the information for scams or targeted fraud.
The company is contacting affected customers, working with cyber specialists to assess the breach, secure systems and provide support. Origin serves about 4.8 million customers across Australia. The company has not disclosed how attackers gained access or whether any customer financial losses have been reported. Law enforcement and cybersecurity teams continue to investigate the incident.








