Origin Energy is looking into a possible violation of customer data.
Australia's largest energy retailer has informed the ASX that there may have been unauthorized access to some customer data, although it claims that credit and bank details seem unaffected. On July 22, Origin Energy, the country’s largest energy provider, announced it is looking into potential unauthorized access to certain customer information.
The company stated that it does not believe that the compromised data includes credit card or bank details, but it did not specify how many individuals may be involved in the incident. This announcement comes during a year marked by numerous corporate breaches, including a supply-chain compromise at Klue that exposed LastPass customer records, followed by another extortion group appearing weeks later with its own demands.
Currently, Origin's statement lacks substantial detail, which may reflect either caution or could indicate the early stages of an investigation that is still unfolding. In its report, Origin indicated that it is treating the incident as urgent and will provide further updates as necessary.
Additionally, the retailer has informed the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner, which oversees the country’s data breach notification scheme. Under this scheme, organizations are generally required to notify affected individuals and the regulator if a breach is deemed likely to cause serious harm—a threshold Origin has not declared it has met.
It remains unclear how the access occurred, the timeline of events, or whether any data has actually been removed from Origin's systems. The company has not identified any specific affected system, third-party vendor, or point of entry, and at the time of the announcement, no threat actor had publicly claimed responsibility.
However, this silence did not last long. As reported by Insurance Business, an individual claiming to have breached Origin contacted The Australian, alleging possession of records belonging to millions of customers and provided a sample of about 50 records that reportedly included names, addresses, dates of birth, phone numbers, and billing history.
This claim has not been independently verified, and Origin has not confirmed the scale of the incident or the types of data involved. If true, the alleged data haul may be less concerning than it could be, particularly because, according to Origin, financial credentials are not among the exposed information. Financial details are the quickest pathway from a breach to fraud, and the company’s initial assessment suggests that card and bank information was not compromised.
While names, addresses, and dates of birth may not prompt immediate alarm, they are more durable and are often used for identity theft and subsequent phishing attempts following any public disclosure. Australia has been grappling with these lessons publicly over recent years, especially following the 2022 breaches involving Optus and Medibank that put millions of personal records into the hands of criminals, leading to a tightening of the country’s privacy laws and heavier penalties for serious or repeated breaches.
Regulators in other regions have observed extortion efforts becoming increasingly bold, with one instance involving a US government entity paying a hefty ransom to attackers who did not even encrypt any files. Patterns from recent incidents, including a breach of an education vendor that exposed data concerning hundreds of millions of students, show that initial reports rarely convey the complete picture.
The number of affected individuals often rises, and the categories of stolen information broaden. It frequently turns out that the vendor at the center of the breach is linked to multiple other companies.
For now, the practical advice for Origin’s customers is to remain vigilant: be alert for unusual emails or phone calls, and view any communication referencing an Origin account with skepticism until the company provides more details.
"We recognize that an incident like this may cause concern," Origin said, acknowledging "the impact of this uncertainty" on those whose data it manages. The company has committed to offer further updates once its investigation progresses. Until then, customers await one crucial detail that will give shape to the disclosure: a specific number and a confirmed account of what has actually occurred.
Other articles
Origin Energy is looking into a possible violation of customer data.
Australia's biggest energy retailer reported to the ASX that it is looking into unauthorized access to customer data, although it seems that card and bank information has not been compromised.
