Origin Energy has confirmed that customer information was compromised in a security incident, turning a brief warning about a possible breach into a live data-exposure case for one of Australia’s biggest household utilities.
The Sydney-based electricity and gas retailer, which serves nearly 5 million customers, said Thursday that it is still trying to determine how many people were affected. The company said it is working with federal agencies, authorities and independent cybersecurity specialists.
Origin said the exposed information may include customer account details, names, addresses and dates of birth. It may also include the last four digits of credit card numbers and the last three digits of bank account numbers.
That list matters because it mixes identity data with partial payment information. Origin has not publicly given a final customer count, and the company’s update did not disclose how the attacker got access.
The confirmation followed a shorter statement Wednesday, when Origin said it was investigating a possible security incident. That came after The Australian reported that a purported hacker had sent the outlet what the person claimed was a sample of stolen Origin records.
Origin says securing systems is the priority
Origin CEO Frank Calabria apologized to customers and said the company was focused on locking down its environment.
“One of our key priorities is taking action to secure our systems and ensure no further unauthorised access,” Calabria said. “We are working with independent cyber experts to support Origin, and that work is continuing alongside the work of authorities.”
Origin’s public account leaves several basic questions unanswered, including the method of intrusion, the period of unauthorized access and whether the incident affected all customer types or only certain accounts. The company said it is still working to understand the total number of impacted customers.
The incident puts another major Australian service provider into breach-response mode. Utilities hold the kind of data attackers can reuse well beyond the original intrusion: names, addresses, dates of birth and account records. Even partial payment details can help criminals make phishing attempts look more convincing when combined with other personal information.
Another breach for Australian customer data
The Origin disclosure follows a separate cyberattack affecting Partnered Health, a major Australian healthcare clinic network. Partnered Health confirmed that patients who attended at least 21 clinics may have had medical records stolen.
There is no public claim in Origin’s statement tying its breach to the Partnered Health incident. The common thread is more mundane and more useful to attackers: large organizations storing sensitive customer or patient records, then having to explain what was taken after access has already happened.
Origin said its investigation is continuing. For now, customers have a partial list of possible exposed fields and no final count of affected accounts.
This story draws on original reporting from The Record.