Origin Energy hack: 900,000 customers affected, CEO apologizes for delay
Origin Energy hack affects 900,000 customers

Origin Energy has admitted it was warned of a hack that accessed 900,000 current and former customers' personal data three weeks before it first made the data breach public. Australia's largest energy retailer said a “significant” proportion of the 900,000 had been former customers, with those affected to be notified in the coming days.

Data Compromised and Customer Impact

The data may include customers' names, addresses, dates of birth, phone numbers and account information, as well as the last four digits of a credit card, or the last three digits of a bank account. Origin has 4.8 million customer accounts in Australia, providing electricity, fossil gas, LPG and internet services to homes and businesses.

CEO Apology and Warning

Origin’s chief executive, Frank Calabria, told reporters the company was still reviewing the incident. “We are sorry,” Calabria said. “We don’t take for granted the trust customers place in Origin and we’re here to support them.” Calabria warned customers to watch out for suspicious activity and a heightened risk of scams.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Timeline of the Hack

Calabria said Origin received emails from someone claiming to have accessed customer records on 2 July. The company did not determine it was a credible threat as there was no proof of data being accessed. Origin received proof that customer data had been accessed on 22 July, at which point it announced the hack. He said “historical data” appeared to have been accessed “on an unauthorised basis” and Origin had worked to secure its system to prevent similar incidents. The company did not believe any information had been put on the dark web.

Investigation and Questions Unanswered

Calabria declined to answer questions over when the breaches had occurred; whether Origin staff had been identified as having a role in the breach; whether a ransom had been sought, paid, or was being considered; and whether the leak risk was “live” or resolved. “It is a criminal matter which is under active investigation and, given that, we are constrained by the level of information we can provide at this time,” he said.

The company last week dismissed reports it had reached a deal with its hacker to avoid data leaks, after The Australian published claims from a person claiming to be behind the hack on Friday. “Origin notes there is considerable media speculation in relation to the data security incident we are actively managing. Our investigation is ongoing, and we currently have no further updates,” an Origin spokesperson said on Friday.

Pickt after-article banner — collaborative shopping lists app with family illustration