Origin Energy investigates potential breach of customer data


Origin Energy investigates potential breach of customer data

Australia’s largest energy retailer has told the ASX that some customer information may have been accessed without authorisation, though it says card and bank details appear untouched.


Origin Energy, Australia’s largest electricity and gas retailer, told the Australian Securities Exchange on 22 July that it is investigating potential unauthorised access to some of its customers’ data.

The company said it does not believe the affected information includes credit card or bank details, though it stopped short of saying how many people had been caught up in the incident.

The disclosure arrives in a year already thick with corporate intrusions, from a supply-chain compromise at Klue that spilled LastPass customer records to the second extortion group that surfaced weeks later to press its own demands.

Origin’s statement is, for now, notably thin on detail, which is either prudence or the early fog of an investigation that has not yet run its course.

In its filing, Origin said its “investigations into this incident are occurring as a matter of urgency,” and that it would “provide further updates as appropriate.”

The retailer added that it had notified the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner, the regulator that oversees the country’s notifiable data breaches scheme.

Under that scheme, an organisation is generally required to alert both affected individuals and the regulator once a breach is judged likely to cause serious harm, a threshold Origin has not said it has reached.

What is not yet clear is how the access occurred, when it began, or whether any data has actually left Origin’s systems.

The company has not named an affected system, a third-party vendor, or a point of entry, and, no threat actor had publicly claimed responsibility at the time of the disclosure.

That silence has not stayed unfilled for long. According to Insurance Business, a person claiming to have breached Origin contacted The Australian and said they held the records of millions of customers, supplying a sample of around 50 records that reportedly included names, addresses, dates of birth, phone numbers, and billing history.

The claim has not been independently verified, and Origin has not confirmed either the scale of the incident or the categories of data involved.

If accurate, the alleged haul would be less alarming than some, precisely because of what Origin says is missing.

Financial credentials are the fastest route from a breach to fraud, and the company’s early read is that card and bank details were not exposed.

Names, addresses, and dates of birth are quieter but more durable, the raw material for identity theft and the wave of phishing that tends to follow any public disclosure.

Australia has spent the past few years learning this lesson in public. The 2022 attacks on Optus and Medibank pushed the personal data of millions into criminal hands and prompted a tightening of the country’s privacy regime, including steeper penalties for serious or repeated breaches.

Regulators elsewhere have watched extortion crews grow bolder still, in one case a US government body paying a seven-figure ransom to attackers who never locked a single file.

The pattern across recent incidents, including the breach of an education vendor that exposed data tied to hundreds of millions of students, is that the first disclosure rarely captures the full picture.

Numbers climb. Categories of stolen data expand. The vendor at the centre turns out to sit between the named company and a dozen others.

For Origin’s customers, the practical advice for now amounts to vigilance: watch for unexpected emails or calls, and treat any message that references an Origin account with suspicion until the company says more.

“We understand an incident like this may raise concerns,” Origin said, acknowledging “the impact of this uncertainty” on the people whose data it holds.

The company has promised a further update once its investigation firms up. Until then, its customers wait on the one detail that turns a disclosure into a story with a shape: a number, and a confirmed account of what actually left the building.

Get the TNW newsletter

Get the most important tech news in your inbox each week.