Cybersecurity
Origin Energy confirms customer data leak; hacker says 'I've dumped over 2 million records'
Australian power producer Origin Energy Limited (Origin) has confirmed that a cybersecurity incident led to the unauthorised access and disclosure of customer data, although the total number of affected customers remains unclear.
"We are working to understand the total number of impacted customers, and we will contact any customers where we can confirm they have been affected," the company said in a statement.
According to Origin, the compromised information for affected customers may include names, addresses, dates of birth, phone numbers, account information, as well as the last four digits of credit cards or the last three digits of bank account numbers.
Origin CEO Frank Calabria apologised for the breach, saying, "I'm sorry this has happened. Customers trust Origin with their information, and I apologise for the impact this may cause."
"We are contacting affected customers, offering support, and have set up a dedicated contact number and additional resources to help manage our response to this incident," Calabria said.
He added that securing the company's systems remains a top priority.
"One of our key priorities is taking action to secure our systems and ensure no further unauthorised access. We are working with independent cyber experts to support Origin, and that work is continuing alongside the work of authorities," the CEO said.
Meanwhile, a person identifying themselves as "John Doe" has claimed responsibility for the attack. In an email to 7NEWS, the individual alleged that they had accessed Origin's customer care systems and stolen the personal data of more than two million customers.
"I've successfully accessed Origin Energy's customer care systems and dumped the private data of over two million Australians who use their services," the email reportedly stated.
"Most are loyal, long-term customers."
The alleged hacker further claimed that repeated attempts to alert the company's board members, security teams and customer care departments went unanswered.
"Despite my outreach to their board members, security teams, and customer care departments, Origin hasn't made a public announcement about the breach or responded to negotiate next steps," the email said.
"They've shown no interest in resolving it before the data goes public."
According to a 7NEWS report, the alleged hacker claimed to have obtained extensive customer information, including full names, email addresses, phone numbers, dates of birth, account numbers, property IDs, addresses and payment-related details, such as transaction counts, dates, amounts and payment status.
The individual, identifying as "John Doe", has reportedly given Origin 14 days to "settle the matter", threatening to publish the entire dataset if the company fails to respond.
Origin has not independently verified the hacker's claims regarding the scale of the alleged breach or the volume of customer data purportedly stolen.
Support Our Journalism
We cannot do without you.. your contribution supports unbiased journalism
IBNS is not driven by any ism- not wokeism, not racism, not skewed secularism, not hyper right-wing or left liberal ideals, nor by any hardline religious beliefs or hyper nationalism. We want to serve you good old objective news, as they are. We do not judge or preach. We let people decide for themselves. We only try to present factual and well-sourced news.
