Origin Energy confirms bank details of 60 customers accessed in breach
Origin Energy has revealed that full bank details belonging to 60 customers were compromised during a July cyber attack, triggering executive pay cuts and ongoing probes.
Origin Energy has completed its review into a data security incident that occurred in July, confirming that full banking and identification details belonging to a small subset of customers were accessed during a cyber attack. The updated findings reveal that approximately 60 customers had their full bank account numbers compromised, while around 100 individuals suffered unauthorized access to their identification document numbers. According to the company, the compromised ID data involved the document numbers only, stressing that no scanned copies of ID documents were affected.
The disclosures expand upon an earlier security incident affecting approximately 900,000 current and former customers. According to Origin Energy reporting by the Abc and reporting from ssbcrack.com, the broader cohort had various combinations of names, addresses, dates of birth, contact phone numbers, account details, and information about personal circumstances accessed. This mass exposure also compromised the last four digits of credit cards or the last three digits of bank accounts, alongside roughly 15,000 numbers linked to government concession schemes or programs.
Media additions
Despite the severe scope of the incident, Origin Energy confirmed that the alleged hacker has not publicly leaked or disclosed any customer data. The breach itself was first brought to light when The Australian
provided a sample of 50 customer records containing billing histories, names, addresses, emails, dates of birth, and phone numbers to the energy retailer, prompting the company to alert authorities to a potential security breach. Investigators have since traced the cyber attack to a call centre operating in the Philippines, linking the breach to a former employee of Accenture in Manila. Accenture runs call centres for Origin, though a spokesperson for Accenture declined to comment when contacted by journalists at the ABC.
Executive accountability measures have already been enacted within the energy company. In its annual report published on Thursday, Origin Energy confirmed that executive bonuses were docked to reflect shared responsibility, recognize the large number of customers involved, and emphasize the importance of system security and customer data. This resulted in CEO Frank Calabria facing a pay reduction of $357,000, alongside decreases of $607,000 for other members of the executive management team. Additional financial penalties remain under consideration by the board pending final investigations, and the retailer noted that financial fallout would be formally integrated into its results for the 2027 financial year.
Corporate communication surrounding the incident has faced scrutiny from cybersecurity specialists. Troy Hunt criticized the latest disclosures from the energy retailer on Friday, arguing that large publicly listed organizations frequently prioritize reputation and shareholder value ahead of transparent customer communication. Within these organisations there is a big component of trying to preserve shareholders' value,
Mr Hunt said via the ABC, adding [Origin is] saying a lot [in this latest announcement] without saying much
and noting he would have preferred to understand more about the hack.
In response to the ongoing risks, Origin Energy stated that it is well advanced in delivering tailored notifications to affected individuals. These alerts include specific breakdowns of compromised data, practical steps for risk mitigation, and support options such as identity monitoring and a year of free credit monitoring. The company has also recommended that customers remain cautious of any unusual or suspicious activity, particularly in communications that appear to originate from Origin, the government, or their bank.
Incident Summary
- Total affected base: Approximately 900,000 current and former customers.
- Full bank accounts accessed: Approximately 60 customers.
- ID document numbers accessed: Approximately 100 customers (numbers only; no scanned copies affected).
- Government concession numbers compromised: Approximately 15,000 customers.
- Origin executive financial penalties: CEO pay reduced by $357,000; other executives reduced by $607,000.
The criminal investigation into the cyber attack remains ongoing, with Origin Energy CEO Frank Calabria stating that the company has substantially completed its review of information accessed for each customer. Origin is coordinating its response alongside federal authorities, the Australian Cyber Security Centre, the National Office of Cyber Security, and the Australian Federal Police.