Origin Energy confirms data breach has exposed customer information

Save

You have reached your maximum number of saved items.

Remove items from your saved list to add more.

AAA

Origin Energy, the largest Australian power and gas company, has confirmed that a hacker has gained unauthorised access to some customers’ private information, including names, addresses and partial credit card and bank account numbers.

The company said on Thursday it was still working to determine how many customers were affected by the cybersecurity breach, and was contacting customers individually once it was confirmed their information had been comprised.

Origin Energy is Australia’s largest power and gas supplier.Chris Hopkins

“I’m sorry this has happened,” Origin Energy chief executive Frank Calabria said. “Customers trust Origin with their information, and I apologise for the impact this may cause.”

Origin, which supplies electricity and gas and broadband to more than 4.7 million customers nationally, said it continued to engage with Australian government agencies, including the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner.

“We are contacting affected customers, offering support and have set up a dedicated contact number and additional resources to help manage our response to this incident.”

Affected customers’ affected data may include their name, address, date of birth, contact phone number, account information, the final four digits of their credit card, and the final six digits of bank accounts, Origin said.

Incomplete credit card or bank account information cannot be used to make purchases or access accounts, the company explained.

On Tuesday, the alleged hacker claimed to have access to the personal details of 2 million Origin Energy customers. However, this claim has not been verified, and Origin is still investigating the scale of the incident.

The data breach comes amid a growing wave of cyber problems plaguing major Australian companies and institutions. Last week, healthcare provider Partnered Health had sensitive medical records and personal information stolen from its national network of GP clinics.

Customers are being urged to monitor their accounts for suspicious activity, change passwords across their utility and email accounts, and be on high alert for targeted phishing scams that leverage the stolen billing histories.

The Business Briefing newsletter delivers major stories, exclusive coverage and expert opinion. Sign up to get it every weekday morning.

Save

You have reached your maximum number of saved items.

Remove items from your saved list to add more.

Nick Toscano is a business reporter for The Age and Sydney Morning Herald.Connect via X or email.

David Swan is the technology editor for The Age and The Sydney Morning Herald. He was previously technology editor for The Australian newspaper.Connect via X or email.