Australian energy provider Origin says data breach exposes client data
by Bill Toulas · BleepingComputerAustralian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers' personally identifiable information (PII).
The company has 4.8 million customers and is currently investigating how many of them have been impacted to inform them of the risk via individual notifications.
Origin Energy is Australia’s largest energy retailer, providing electricity, natural gas, and broadband internet services to millions of clients across the country.
The company is listed on the ASX, has annual revenue of $8.5 billion, and holds a 20% ownership stake in the UK’s renewable energy retailer Octopus.
Yesterday, Origin announced that it had launched an investigation into “a potential security incident that may involve unauthorized access to some customers’ data.”
An update published today confirms a data breach, listing the following data types as potentially exposed:
- Full name
- Physical address
- Date of birth
- Phone number
- Account information
- Last four digits of credit card
- Last three digits of bank account
The company noted that the exposed financial details are “incomplete” and cannot be used to hijack accounts or make unauthorized charges to clients’ bank accounts.
Origin CEO, Frank Calabria, apologized to customers for the sensitive data being exposed, and assured them that the company is taking steps to block further unauthorized access.
Also, confirmed impacted clients are being contacted directly and offered support via a dedicated portal and related resources.
Origin has informed the Australian Federal Police (AFP), the Australian Cyber Security Centre, and the Office of the Australian Information Commissioner about the incident, and continues to engage with the agencies as needed.
Hackers claim large-scale data theft
Local media outlet 7news reported that before Origin Energy released its second statement, a threat actor identifying as “John Doe” contacted them to claim the breach.
The threat actor alleged to be holding the data types for 2 million Origin customers.
Source: 7news
The hacker claimed that they contacted security teams, customer support, and even board executives, without receiving a response.
The hacker has set up a site where he threatens to leak the stolen data in two weeks unless Origin contacts them via Signal to negotiate a solution.
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.