Australia’s largest electricity and gas retailer has confirmed that the personal information of about 900,000 current and former customers was hacked in a major cybersecurity incident.
Origin Energy chief executive Frank Calabria issued an apology to customers on Tuesday and said the company had begun contacting affected individuals to offer identity-protection and cyber support services.
“At this point in time, we believe the information of approximately 900,000 current and former customers was accessed,” Origin chief executive Frank Calabria said.
“To our customers, I am sorry. We don’t take for granted the trust customers place in Origin and our safeguarding of their information.”
Origin first disclosed the threat of a data breach to customers and the market last week. Affected customers’ data may include their name, address, date of birth, contact phone number, account information, the final four digits of their credit card, and the final three digits of bank accounts, it said.
Calabria on Tuesday also provided new detail on the timeline leading up to the beach becoming public.
The company had been reviewing what it described as a “potential security threat” since early July, but the available information at the time led it to believe the threat was not credible, he said.
That assessment changed on July 22, when new information emerged indicating that a security breach may have occurred. Origin said it immediately notified the market and alerted customers as a precaution.
“Importantly, this is a criminal matter that is subject to an ongoing investigation by the relevant authorities, and given this, we are constrained by the level of information we can provide about the incident at this time,” Calabria said.
Origin’s data breach adds to a growing list of Australian organisations and institutions that have suffered cyber major cybersecurity problems in recent years, including Optus, Qantas and Medibank. Earlier this month, healthcare provider Partnered Health had sensitive medical records and personal information stolen from its national network of GP clinics.
Origin warned customers to be cautious of unexpected calls, emails or text messages referring to their Origin accounts, and urged them not to click on links in unsolicited messages. It also said they should independently verify anyone claiming to represent the company through official contact channels, and never disclose passwords or sensitive personal or financial information unless they were certain who they were dealing with.
Customers were also encouraged to enable to-step authentication on email and other online accounts wherever possible.
“We are acutely aware that others may exploit this incident, including by impersonating Origin or through other scam activity,” Calabria said. “We recommend that all our customers remain vigilant to suspicious activity and a heightened risk of scams.”
The Business Briefing newsletter delivers major stories, exclusive coverage and expert opinion. Sign up to get it every weekday morning.