Business

Origin Energy admits three-week delay in disclosing cyberattack affecting 900,000 customers

Chief executive apologises as company clarifies that a significant proportion of affected individuals are former customers, while denying reports of a ransom deal with the hacker

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: The Guardian Business · original
Business
No image available
Australia’s largest energy retailer faces scrutiny over timeline after CEO Frank Calabria confirms warning emails were received on 2 July but breach was not verified until 22 July

Origin Energy has acknowledged it received initial warnings of a cyberattack three weeks before publicly disclosing that the personal data of approximately 900,000 current and former customers had been compromised. The Australia-based energy retailer confirmed on Tuesday that it received emails on 2 July from an individual claiming to have accessed customer records, but did not verify the threat or go public until 22 July, citing a lack of initial proof.

Chief executive Frank Calabria issued an apology to customers, stating the company does not take for granted the trust placed in Origin. He advised affected individuals to remain vigilant against suspicious activity, warning of a heightened risk of scams as the company begins notifying customers in the coming days. Calabria noted that a "significant" proportion of the 900,000 affected individuals are former customers.

The compromised data includes names, addresses, dates of birth, phone numbers, account details, and partial financial information, specifically the last four digits of credit cards or the last three digits of bank accounts. Origin Energy, which holds 4.8 million customer accounts across electricity, fossil gas, LPG, and internet services, stated it does not believe the data has been released on the dark web.

Calabria declined to provide specific details regarding the exact timeline of the initial breach, potential staff involvement, or whether a ransom was sought or paid. He explained that the incident is a criminal matter under active investigation, which constrains the level of information the company can publicly provide. Origin also dismissed recent reports suggesting it had reached a deal with the hacker to prevent data leaks, following claims published by The Australian.

The company is currently working to secure its systems to prevent similar incidents, with Calabria describing the accessed information as "historical data" obtained on an unauthorised basis. As the investigation continues, Origin has maintained that it has no further updates to share regarding the status of the leak risk or the identity of the perpetrators.

Continue reading

More from Business

Read next: Iran holds Strait of Hormuz talks with Saudi Arabia and Oman as Trump praises diplomacy
Read next: Kospi and Nasdaq 100 correlation hits five-year high
Read next: Oil prices drop more than 2% as U.S.-Iran tensions ease