Australian energy provider Origin Energy disclosed a data breach impacting customer data

Origin Energy confirmed a data breach after a hacker claimed to have stolen data from 2 million customers and threatened to leak it.
Origin Energy disclosed a cyberattack that exposed customer data after a hacker claimed to have stolen records belonging to 2 million customers and threatened to publish them. An alleged hacker calling themselves “John Doe” claimed responsibility for the Origin Energy breach, saying they accessed the company’s customer systems and stole customers’ personal data.
“Most are loyal, long-term customers,” reads an email sent by the hacker to Australian media outlet 7News.
“Despite my outreach to their board members, security teams, and customer care departments, Origin hasn’t made a public announcement about the breach or responded to negotiate next steps.
“They’ve shown no interest in resolving it before the data goes public.”

The claim prompted an urgent investigation by the Australian energy provider.
The Australian energy provider said unauthorized access affected some customer information and is still investigating the incident to determine how many people were impacted.
“Origin can confirm there has been unauthorised access and disclosure of some customers’ data. We are working to understand the total number of impacted customers, and we will contact any customers where we can confirm they have been affected.” reads the update on data security incident published by the company on July 23.
“For affected customers, impacted data may include name, address, date of birth, contact phone number and account information, as well as the last four digits of a credit card, or the last three digits of a bank account. Incomplete credit card or bank account information cannot be used to make purchases or access accounts.”
Origin Energy is one of Australia’s largest integrated energy companies, with approximately 4.8 million customers. Headquartered in Sydney, it operates across the electricity and natural gas sectors.
The firm is investigating the security breach with the help of external cybersecurity experts.
The company said the attacker may have stolen customers’ names, addresses, dates of birth, phone numbers, account details, and partial payment card or bank account numbers. The energy firm is notifying affected customers and has informed Australian law enforcement, cyber, and privacy authorities, including the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner.
Origin Energy pointed out that its operations have not been impacted.
The “John Doe” gave Origin 14 days to respond and threatened to release the stolen data if the company does not reach an agreement.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, newsletter)

