Origin Energy investigates breach as hacker claims data of millions

The company is investigating a potential data breach, sharpening scrutiny of corporate cyber exposure and disclosure timing for brokers

Origin Energy investigates breach as hacker claims data of millions

Cyber

By Daniel Wood

Origin Energy has confirmed it is investigating a potential security incident that may have exposed some customers' data, becoming the latest major Australian company to face a cyber incident in a year already marked by high-profile breaches.

"Origin Energy Limited (Origin) is currently investigating a potential security incident which may involve unauthorised access to some customers' data," said the energy giant in a media release. "We do not believe the impacted data includes customer credit card or bank details."

The company acknowledged the uncertainty the incident may cause. "We understand an incident like this may raise concerns and acknowledge the impact of this uncertainty on Origin customers," it said. "Our investigations into this incident are occurring as a matter of urgency, and Origin will provide further updates as appropriate."

Origin said it has notified the Australian Cyber Security Centre and the Australian Federal Police and is engaging with the Office of the Australian Information Commissioner.

Hacker claims access to millions of records

According to ABC News, Origin's statement followed contact from The Australian, which reported that a hacker had sent it a sample of 50 customer records containing names, addresses, emails, dates of birth, phone numbers and bill history. The ABC said it could not immediately verify these claims. Reuters, which also confirmed the investigation, reported that Origin did not provide further detail on the nature of the impacted data.

Origin Energy serves more than 4.7 million customers across Australia and shares in the company dropped 2.5% following the announcement.

Part of a wider pattern of Australian breaches

The incident adds to a run of significant cyber events affecting Australian companies. Partnered Health, which operates a network of GP clinics, was targeted in a cyber attack only last week, with sensitive medical records and personal information stolen. In 2022 there were major breaches at Optus and Medibank.

For brokers advising corporate and cyber clients, the Origin incident underscores a pattern regulators have been flagging for some time: the speed and completeness of a company's public disclosure can shape reputational and regulatory outcomes as much as the technical scope of the breach itself. Origin's statement, issued the same day it was approached by media, reflects the kind of rapid, cautious disclosure increasingly expected of large corporates handling customer data, even before the full scope of an incident is confirmed.

The case also highlights a recurring feature of cyber incidents: the gap between what a company can confirm internally and what a threat actor claims externally. The alleged hacker's claim of access to millions of records remains unverified. Brokers advising clients on cyber cover, incident response planning and breach notification obligations will be watching closely for Origin's next update and for confirmation of the actual scope of any compromised data.

Origin said further updates would be provided as its investigation progresses.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!