Origin Energy has acknowledged that it received a warning about the hack compromising the personal data of 900,000 current and former customers three weeks before the breach was made public.
Australia's largest energy retailer stated that a significant portion of the affected individuals are former customers, with notifications to be sent in the coming days.
Data Compromised
The stolen data may include names, addresses, dates of birth, phone numbers, and account information, along with the last four digits of credit cards or the last three digits of bank accounts. Origin Energy has 4.8 million customer accounts across Australia, supplying electricity, gas, LPG, and internet services.
CEO's Apology
Chief Executive Frank Calabria expressed regret, stating, “We are sorry. We don’t take for granted the trust customers place in Origin and we’re here to support them.” He urged customers to watch for suspicious activity and heightened scam risks.
Origin received an email on 2 July from someone claiming to have accessed customer records. However, the company did not initially consider it a credible threat due to a lack of proof. It wasn't until 22 July, when evidence of data access was provided, that the hack was announced.
Investigation Ongoing
Calabria noted that historical data appeared to have been accessed without authorisation, and measures have been taken to secure the system. There is no indication that the data has been posted on the dark web. He declined to answer questions about when the breach occurred, whether staff were involved, if a ransom was demanded or paid, or if the risk is ongoing, citing an active criminal investigation.
Last week, Origin dismissed reports of a deal with the hacker to prevent data leaks, following claims published in The Australian.



