The Australian energy provider says information belonging to current and former customers was accessed without authorisation. Chief executive Frank Calabria has apologised and urged customers to remain alert to scams and identity theft
Around 900,000 current and former Origin Energy customers may have been affected by a major cyber security breach.
The Australian energy provider has confirmed that customer information was accessed without authorisation during a recent security incident.
Origin has completed the initial phase of its investigation and says it will contact customers whose data was involved.
The company has also extended customer support hours and made specialist cyber security and identity protection services available to affected people.
Chief Executive Apologises
Origin chief executive Frank Calabria issued a public apology.
“To our customers, I am sorry. We don’t take for granted the trust customers place in Origin and our safeguarding of their information,” he said.
Calabria said the company was working with cyber security and forensic specialists to contain the breach and strengthen its systems.
Origin is also cooperating with government agencies and relevant authorities as the investigation continues.
The company has described the incident as a criminal matter.
First Warning Emerged in Early July
Origin said it first became aware of a possible security threat in early July.
At that stage, the threat was not considered credible based on the information available.
The situation changed on July 22, when new details suggested that a data breach may have taken place.
Origin then launched further investigations, updated the market and warned customers as a precaution.
The company will now face questions about why the initial warning was dismissed and whether earlier action could have reduced the scale of the incident.
What Information Was Accessed?
Origin has not yet released a complete list of the customer information involved.
The company confirmed that customer data had been accessed but said it was limited in what it could disclose because a criminal investigation was underway.
Affected customers are expected to receive direct information explaining what data was exposed and what protective steps they should take.
Until more details are available, current and former customers should be alert to the risk of highly convincing scam messages.
Criminals may pose as Origin representatives, banks, government agencies or technical support workers and ask victims to provide passwords, verification codes, identity documents or payment details.
Warning Over Scams
Origin has urged customers to remain vigilant.
A breach of this size could lead to phishing emails, text messages and fraudulent phone calls.
Customers should avoid opening links from unknown senders and should never provide passwords, security codes or banking details to unsolicited callers.
Even messages containing a person’s name, address or energy account information should not automatically be trusted. Stolen data can be used to make scams appear legitimate.
Customers should access their Origin account through the official website or app rather than through links received by email or text message.
What Customers Should Do
People contacted by Origin should carefully follow the company’s instructions and confirm exactly what information was exposed.
Customers should consider changing their Origin password, particularly if the same password is used for other online services.
Passwords should be unique, and multi-factor authentication should be enabled wherever possible.
Customers should also monitor bank transactions, credit applications, bills and any unusual activity linked to their personal accounts.
Requests for urgent payments, identity confirmation or remote access to a computer should be treated as potential fraud.
Support for Affected Customers
Origin has made specialist identity and cyber support services available to customers affected by the breach.
Customer service hours have also been extended to deal with an expected increase in enquiries.
The company will need to show that it can not only contain the incident but also provide meaningful assistance to those at risk of identity theft and financial scams.
Clear communication will be essential. Customers need to know what was accessed, when it happened and what steps are genuinely necessary to protect themselves.
Origin Shares Fall
The announcement also affected the company’s market value.
Origin Energy shares were down more than 2 per cent by 11am AEST on Tuesday.
The decline reflected investor concerns about investigation costs, possible legal consequences and reputational damage.
A breach involving approximately 900,000 people may lead to significant expenses for forensic investigations, customer support, system upgrades and potential regulatory action.
A Major Test of Public Trust
The incident raises broader concerns about the protection of personal information held by major Australian companies.
Energy providers collect and retain significant amounts of customer data, sometimes continuing to store it after a customer has changed suppliers.
The involvement of former customers highlights the importance of limiting how long personal information is retained and ensuring that stored data remains properly protected.
Origin must now explain how the breach occurred, why the initial warning was not considered credible and how it intends to prevent a similar incident in the future.
For nearly one million Australians, the most immediate concern is whether their personal information will now be used in scams or identity fraud.
