Australian vitality supplier Origin Power has confirmed an information breach by an unknown attacker, confirming that clients’ personally identifiable info (PII) was compromised.
The corporate has 4.8 million clients and is at the moment investigating what number of of them had been affected and informing them of the dangers with particular person notifications.
Origin Power is Australia’s largest vitality retailer, offering electrical energy, pure fuel and broadband web providers to thousands and thousands of shoppers throughout the nation.
The corporate is listed on the ASX, has annual gross sales of $8.5 billion and holds a 20% stake in UK renewable vitality retailer Octopus.
Yesterday, Origin introduced that it had begun an investigation right into a “potential safety incident which will contain unauthorized entry to some buyer information.”
An replace printed right this moment confirms an information breach and lists the next information varieties as probably uncovered:
- full title
- bodily handle
- date of beginning
- phone quantity
- Account info
- Final 4 digits of bank card
- Final 3 digits of checking account
The corporate stated the monetary particulars uncovered had been “incomplete” and couldn’t be used to take over accounts or fraudulently cost clients’ financial institution accounts.
Origin CEO Frank Calabria apologized to clients for the publicity of delicate information and warranted them that steps had been being taken to dam additional unauthorized entry.
Shoppers recognized as being affected will even be contacted straight and supplied assist via a devoted portal and related assets.
Origin has reported this incident to the Australian Federal Police (AFP), the Australian Cyber Safety Heart and the Australian Info Commissioner’s Workplace and can proceed to liaise with businesses as applicable.
Hackers declare huge information theft
Earlier than Origin Power launched its second assertion, native media outlet 7news reported that an attacker calling itself “John Doe” had contacted the corporate to say a breach.
The attackers declare to have information varieties for two million Origin clients.

Supply: 7news
The hackers claimed they contacted the safety workforce, buyer assist, and even the board of administrators, however obtained no response.
The hackers have arrange a website threatening to leak the stolen information inside two weeks except Origin contacts them by way of Sign to barter a decision.
Safety groups doc 54% of profitable assaults and difficulty a warning on solely 14%. The remainder strikes invisibly via the surroundings.
Picus’ whitepaper exhibits how one can check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
