Origin Energy, Australia's largest energy retailer, has disclosed that a hack accessed the personal data of approximately 900,000 current and former customers. The company admitted it was warned about the breach three weeks before publicly announcing it.
The compromised data may include customers' names, addresses, dates of birth, phone numbers, and account information. It could also include the last four digits of credit cards or the last three digits of bank accounts. Origin Energy has stated that a significant proportion of those affected were former customers, and notifications will be sent in the coming days.
Origin's chief executive, Frank Calabria, apologised for the incident and advised customers to watch out for suspicious activity and an increased risk of scams. Calabria stated that the company received emails claiming data access on 2 July but did not deem it a credible threat without proof. Proof of customer data access was received on 22 July, leading to the public announcement.
Calabria indicated that "historical data" appeared to have been accessed "on an unauthorised basis" and that Origin had worked to secure its system. He added that the company does not believe any information has been placed on the dark web. Calabria declined to answer questions regarding the timing of the breaches, staff involvement, or ransom demands, citing an active criminal investigation.