Australian Energy Provider Origin Confirms Data Breach Exposing Client Information to Threat Actors
A significant data breach has been confirmed by Australian energy provider Origin Energy, exposing the personally identifiable information (PII) of an unknown number of its 4.8 million customers. The company is currently investigating the scope of the breach and will notify affected clients directly.
Origin Energy, Australia’s largest energy retailer, provides electricity, natural gas, and broadband internet services to millions across the country. The data breach involves unauthorized access to sensitive customer information, including full names, physical addresses, dates of birth, phone numbers, account details, last four digits of credit card numbers, and last three digits of bank account numbers. However, the company has stated that the exposed financial details are incomplete and cannot be used for malicious activities such as hijacking accounts or making unauthorized charges.
The breach was first reported by Origin Energy yesterday, with a statement announcing an investigation into “a potential security incident” involving unauthorized access to customer data. An update today confirmed the breach, listing the types of data potentially exposed. The company has apologized to customers and assured them that it is taking steps to block further unauthorized access.
In a concerning development, local media outlet 7news reported that before Origin Energy’s second statement was released, a threat actor claiming to be holding data for 2 million Origin customers contacted them. The hacker, identifying as “John Doe,” has set up a website threatening to leak the stolen data in two weeks unless Origin contacts them via Signal to negotiate a solution.
The breach raises concerns about the security of sensitive customer information and the potential consequences of a large-scale data theft. As Origin Energy continues to investigate the scope of the breach and inform affected clients, it is essential for customers to remain vigilant and take steps to protect their personal data.
In an era where cybersecurity threats are increasingly sophisticated, it’s crucial for organizations like Origin Energy to prioritize security measures and incident response planning. This includes regular testing of systems, employee training on cybersecurity best practices, and collaboration with law enforcement agencies in the event of a breach. By taking proactive steps to secure customer data, companies can minimize the risk of a devastating data breach.
In practical terms, customers impacted by the Origin Energy data breach should remain cautious and monitor their accounts closely for any suspicious activity. They should also change passwords and security questions to prevent potential identity theft or account hijacking. Additionally, customers may want to consider taking proactive steps to protect their personal data, such as implementing multi-factor authentication on online accounts and regularly reviewing credit reports.
Source: Bleeping Computer — 2026-07-23