Origin Energy Confirms Data Breach, Millions of Customer Details Potentially Exposed
Australian energy giant **Origin Energy** has confirmed a significant data breach impacting its vast customer base. While the company is still assessing the full extent, personal and limited financial information of potentially millions of customers has been compromised. An unknown threat actor claims responsibility, alleging a much larger data theft and threatening public release.
Australia's largest energy retailer, **Origin Energy**, has disclosed a data breach following unauthorized access to customer data. The incident, currently under investigation, has exposed personally identifiable information (PII) for an undetermined number of its 4.8 million customers.
**Origin Energy**, which provides electricity, natural gas, and broadband internet across Australia, initially announced a "potential security incident" and has since confirmed the breach, detailing the types of data potentially compromised.
### Exposed Data Types
The company's update confirms that the following customer data may have been accessed:
* Full name
* Physical address
* Date of birth
* Phone number
* Account information
* Last four digits of credit card
* Last three digits of bank account
**Origin Energy** has stressed that the financial details exposed are "incomplete" and insufficient for unauthorized account hijacking or fraudulent transactions.
**Frank Calabria**, CEO of **Origin Energy**, has issued an apology to customers, assuring them that measures are being taken to prevent further unauthorized access. Impacted customers will receive direct notification and support via a dedicated portal and resources.
The incident has been reported to the **Australian Federal Police (AFP)**, the **Australian Cyber Security Centre**, and the **Office of the Australian Information Commissioner**, with **Origin Energy** continuing to engage with these agencies.
### Hacker Claims Large-Scale Theft and Ransom Threat
Prior to **Origin Energy**'s second statement, a threat actor identifying as "**John Doe**" reportedly contacted local media outlet **7news**, claiming responsibility for the breach. The hacker alleged to possess data belonging to 2 million **Origin Energy** customers.

According to **7news**, the threat actor claimed to have attempted contact with **Origin Energy**'s security teams, customer support, and even board executives without success. "**John Doe**" has since established a website, threatening to leak the stolen data within two weeks unless **Origin Energy** initiates contact via **Signal** to negotiate a resolution.
This incident underscores the persistent and evolving threat landscape facing critical infrastructure providers and highlights the importance of robust cybersecurity defenses and incident response protocols.