Origin Energy Confirms Data Breach Exposing Customer Data

Australia's largest energy retailer confirms data breach exposing customer PII and launches investigation with federal authorities.

By Central
The breach exposed full names, addresses, and partial financial details of Origin Energy customers.
Highlights
  • Origin Energy confirmed a data breach that exposed personally identifiable information of its customers.
  • A threat actor claiming to hold data of 2 million customers threatened to leak the information.
  • The breach highlights the growing threat to energy sector companies and consumer data security.

Australia’s largest energy retailer, Origin Energy, has confirmed a data breach that exposed customers’ personally identifiable information (PII), prompting an investigation alongside federal law enforcement. The company, which supplies electricity, natural gas, and broadband internet to 4.8 million customers, disclosed that an unknown threat actor gained unauthorized access to certain customer records. Origin is currently working to determine the full scope of the incident and has begun notifying impacted individuals directly.

What Data Was Exposed in the Origin Energy Breach

According to an official update from Origin, the compromised data includes full names, physical addresses, dates of birth, phone numbers, and account information. The breach also exposed partial financial details: the last four digits of credit cards and the last three digits of bank account numbers. The company emphasized that these financial fragments are incomplete and cannot be used to hijack accounts or initiate unauthorized charges. Origin CEO Frank Calabria has apologized to customers and stated that steps are being taken to prevent further unauthorized access. The company has reported the incident to the Australian Federal Police, the Australian Cyber Security Centre, and the Office of the Australian Information Commissioner.

Hacker Claims to Hold Data of 2 Million Customers

Before Origin published its second statement, a threat actor using the alias “John Doe” contacted local media outlet 7news to claim responsibility for the breach. The hacker alleged to be in possession of PII for 2 million Origin customers and stated that they had attempted to contact Origin’s security team, customer support, and board executives — reportedly receiving no response. The threat actor has set up a site where they threaten to leak the stolen data within two weeks unless Origin initiates contact via Signal to negotiate a resolution. These claims remain unconfirmed by Origin, which continues its investigation.

Why This Breach Matters for Energy Sector Security

The Origin Energy incident underscores the escalating threat to critical infrastructure and large consumer-facing utility providers. With annual revenue of $8.5 billion and a 20% stake in UK renewable retailer Octopus, Origin is a major player in the energy market. Breaches of this scale expose millions of individuals to risks of identity theft, phishing, and social engineering attacks. The exposure of partial financial data, while not directly usable for fraud, still provides threat actors with enough context to craft convincing targeted attacks. This incident aligns with a broader trend where attackers increasingly target energy and utility companies — not only for operational disruption but also for the rich consumer data they hold.

What Affected Customers Should Do Now

If you are an Origin Energy customer, take immediate steps to protect your accounts and personal information. First, change your Origin account password and ensure you use a strong, unique password that you do not reuse on other services. Enable two-factor authentication (2FA) on your Origin account and any other online accounts that support it. Monitor your bank and credit card statements closely for any unauthorized transactions, even small ones that might indicate a test charge. Consider placing a fraud alert or credit freeze with major credit reporting bureaus in your country. Be highly skeptical of unsolicited phone calls, emails, or text messages that reference the breach — threat actors will use this event to launch phishing campaigns. Use a reputable no-log VPN service when accessing sensitive accounts over public Wi-Fi to add an extra layer of encryption. Finally, consider using a zero-knowledge password manager to generate and store strong, unique passwords for every site, reducing the risk of credential stuffing attacks.

Share This Article