Origin Energy confirms 900,000 customers hit in data breach

Origin discloses the scale of its data security incident, well below the hacker's reported claim

Origin Energy confirms 900,000 customers hit in data breach

Cyber

By Daniel Wood

Origin Energy says that the personal information of approximately 900,000 current and former customers was accessed in its cyber incident. In a media release, the company said it has now completed the initial phase of its review of the event, giving the market its first confirmed figure since the breach was disclosed.

"At this point in time, we believe the information of approximately 900,000 current and former customers was accessed," CEO Frank Calabria (pictured) said in a statement. "To our customers, I am sorry. We don't take for granted the trust customers place in Origin and our safeguarding of their information."

What changed in today's update

The firm also provided a clearer timeline: It had been assessing a potential security threat since early July but did not initially consider it credible, before new information emerging on 22 July indicated a security incident may have occurred. Calabria described the matter as now subject to a criminal investigation by relevant authorities, which he said limits how much detail Origin can currently disclose.

Origin said it continues to work with the Australian Cyber Security Centre (ACSC), the National Office of Cyber Security (NOCS) and the Australian Federal Police (AFP) and has notified the Office of the Australian Information Commissioner (OAIC), the regulator overseeing Australia's Notifiable Data Breaches scheme. The company has extended its customer support hours and established a dedicated contact line for affected customers, alongside specialist identity and cyber support services.

A gap brokers should be watching

Origin's confirmed figure sits well below the hacker's claim. As Insurance Business has reported, a hacker claimed to have accessed the data of millions of customers when the breach first came to light. Separate reporting has since raised questions over whether a terminated employee's unrevoked credentials on a vendor system played a role in the incident, potentially exposing a larger volume of records than the company has so far confirmed. Origin has not addressed that detail directly, referring instead to its formal ASX statements. Until the criminal investigation concludes, the gap between Origin's own figure and the higher numbers circulating externally remains unresolved and it's a gap that could have direct consequences for how the eventual claims and liability picture takes shape.

For brokers and insurers with cyber-exposed clients, that scale question is the one to track. Notification costs, potential class action exposure and the eventual reinsurance and quota-share implications for whichever insurer sits behind Origin's cyber liability programme could look very different depending on which number ultimately holds up. Origin, which serves approximately 4.8 million customer accounts across electricity, gas, LPG and internet services, is a company of comparable scale to Optus and Medibank when each confirmed its own major breach in 2022 – though the number of customers Origin has so far confirmed as affected, at 900,000, is considerably smaller than either of those incidents.

Origin said its review into the incident is continuing, and customers with questions can contact the company on its dedicated line or via email.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!