Overview
- Origin first signalled a potential security incident on Wednesday and on Thursday confirmed there had been unauthorised access and disclosure of some customer data.
- The company says exposed information may include names, addresses, dates of birth, phone numbers, account records and the last four digits of some credit cards or the last three digits of some bank accounts.
- A person identifying as "John Doe" told media they hold data for about two million customers and demanded Origin make contact within 14 days, a claim that has been reported but not independently verified.
- Origin has begun contacting affected customers, set up a dedicated help line, engaged independent cyber experts and notified the Australian Cyber Security Centre, the AFP and the OAIC, and its shares fell about 2–3 percent after the news.
- Experts warn the stolen personal data can fuel targeted phishing, identity fraud and AI-enhanced impersonation, so customers should watch for unsolicited messages, avoid clicking unknown links, monitor accounts and enable strong passwords and two-factor authentication.