Particle.news

Origin Energy Confirms Unauthorised Access to Customer Data

Regulators alongside independent cyber specialists are investigating the breach's scope.

Overview

  • Origin confirmed on Thursday that some customer records were accessed and disclosed and that it is contacting customers once it can confirm they were affected.
  • The company said exposed fields may include names, addresses, dates of birth, phone numbers, account details and partial credit‑card or bank digits but does not believe full card or bank credentials were taken.
  • Origin notified the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner and has engaged independent cyber experts to contain the incident.
  • A person claiming to be a hacker calling themself 'John Doe' has told media they hold data on about two million customers and demanded contact within 14 days, though that claim has not been independently verified.
  • The breach has pushed Origin's shares down roughly 2–3% and adds to recent large Australian hacks, raising risks of targeted phishing and identity fraud for affected customers and a need for heightened vigilance.