<.p>Australian energy provider Origin Energy confirmed a data breach exposing customer personal information, prompting an active investigation into the scope of the incident. According to company statements, the breach potentially impacts customers’ full names, physical addresses, dates of birth, phone numbers, account details, and partial financial information.
Origin Energy, Australia’s largest energy retailer with 4.8 million customers, announced the security incident after detecting unauthorized access to customer data. The company provides electricity, natural gas, and broadband services nationwide, holds an $8.5 billion annual revenue, and maintains a 20% stake in the UK renewable energy retailer Octopus, according to corporate disclosures.
Exposed Data and Financial Security Risk
The company confirmed that the exposed records include full names, physical addresses, dates of birth, phone numbers, account information, the last four digits of credit cards, and the last three digits of bank accounts. Origin Energy stated that these financial details are incomplete and cannot be used by unauthorized parties to hijack accounts or execute direct financial charges.
Origin CEO Frank Calabria issued an apology to affected customers and outlined ongoing technical efforts to block further unauthorized access. Impacted clients are receiving direct notifications alongside support resources and access to a dedicated assistance portal.
Regulatory Notification and Extortion Claims
Origin reported the security breach to the Australian Federal Police (AFP), the Australian Cyber Security Centre, and the Office of the Australian Information Commissioner, maintaining active collaboration with these agencies. The notification process runs concurrently with an internal forensic investigation to determine the exact number of individuals affected.
Local media outlet 7news reported that a threat actor operating under the alias “John Doe” contacted journalists prior to the official company disclosure, claiming to hold records for 2 million Origin customers. The individual alleged they attempted to contact security teams and company executives without receiving a response, and subsequently established a site threatening to release the data unless contacted via Signal.