Australian energy provider Origin says data breach exposes client data

Australia’s Largest Energy Provider Origin Suffers Data Breach Exposing Millions of Customers’ Personal Details

In a major security incident, Australia’s largest energy retailer Origin Energy has confirmed that an unknown threat actor breached its systems, exposing sensitive customer data. The company, which serves 4.8 million customers across the country, is now investigating how many clients have been impacted and informing them of the risk.

Origin Energy is one of the leading providers of electricity, natural gas, and broadband internet services in Australia, with annual revenue exceeding $8.5 billion. The company has a significant presence in the market, listing on the Australian Securities Exchange (ASX) and holding a 20% stake in UK-based renewable energy retailer Octopus.

The data breach is believed to have exposed customers’ personally identifiable information (PII), including full name, physical address, date of birth, phone number, account details, last four digits of credit card numbers, and last three digits of bank account numbers. While the company assures that the exposed financial details are incomplete and cannot be used for unauthorized transactions or account takeovers, customers’ sensitive information is still at risk.

Origin Energy’s CEO Frank Calabria has apologized to affected customers and assured them that the company is taking steps to block further unauthorized access. The company has also notified the Australian Federal Police (AFP), the Australian Cyber Security Centre, and the Office of the Australian Information Commissioner about the incident. Impacted clients are being contacted directly and offered support through a dedicated portal and resources.

In an unusual twist, a threat actor claiming to be “John Doe” contacted local media outlet 7news before Origin Energy’s public statement, alleging that they had accessed sensitive data for approximately 2 million customers. The hacker claimed that they attempted to contact the company’s security teams, customer support, and even board executives without receiving a response.

The incident highlights the importance of proactive security measures and continuous monitoring in preventing large-scale breaches. As hackers increasingly employ sophisticated tactics to evade detection, it is crucial for companies to test their defenses regularly to ensure that all layers of security are robust enough to withstand potential attacks.

In light of this incident, Origin Energy customers should remain vigilant and take immediate action to protect themselves from potential data misuse. It’s essential to monitor bank and credit card statements closely and report any suspicious transactions to the relevant authorities. Additionally, customers can take steps to strengthen their online security by using strong passwords, enabling two-factor authentication, and keeping software up-to-date.

As a best practice, companies should conduct regular breach and attack simulation tests to identify vulnerabilities in their systems and ensure that detection tools are effective in identifying potential threats before they escalate into major incidents. By taking proactive measures and prioritizing cybersecurity, organizations can reduce the risk of data breaches and protect sensitive customer information.


Source: Bleeping Computer — 2026-07-23