Origin Energy confirms unauthorised access to customer data in Australia
Origin Energy has confirmed that some customer data was accessed and disclosed without authorisation in a cyber incident affecting the Australian energy retailer. The company said it is still working to determine how many customers were affected. It said it will contact customers once it has confirmed who is impacted.
Sponsored
In a statement released through the Australian Securities Exchange, Origin said the affected information may include names, addresses, dates of birth, contact phone numbers and account details. It also said the data could include the last four digits of a credit card or the last three digits of a bank account. Chief executive Frank Calabria said customers trust the company with their information and apologised for the impact the incident may cause.
Origin said one of its immediate priorities is securing its systems and preventing any further unauthorised access. The company had already told customers by email that it did not believe the compromised information included full credit card or bank details. It first said it was investigating a potential breach the previous day, before confirming the unauthorised access and disclosure.
The incident matters because Origin is one of Australia's largest energy retailers, with more than 4.8 million customers across electricity, gas and LPG services. A breach involving customer identity and account information can create risks of fraud, phishing and wider privacy harm, even where full payment details are not exposed. It also places pressure on the company to show it can contain the incident and communicate clearly with customers and regulators.
Sponsored
The case comes amid continuing concern in Australia about cyberattacks on large organisations and the exposure of personal data. Energy companies are particularly sensitive targets because they hold large volumes of customer records and provide essential services. The company's disclosure through the stock exchange also shows the incident has become a material corporate and regulatory issue, not just a technical one.
What remains unclear is the total number of affected customers and how the unauthorised access occurred. It is also not yet confirmed whether the data was taken from a single system or multiple systems, or whether any further disclosure has taken place. The next developments are likely to include direct customer notifications, further security updates from Origin and any findings from the company's continuing investigation.
#OriginEnergy #cyberbreach #customerdata #Australia #unauthorisedaccess

