Australian energy provider Origin Energy has revealed it is investigating a potential data breach in a filing to the Australian Stock Exchange.
“Origin Energy Limited (Origin) is currently investigating a potential security incident which may involve unauthorised access to some customers’ data. We do not believe the impacted data includes customer credit card or bank details,” the company said in a statement published at 12.42 pm on 22 July.
“We understand an incident like this may raise concerns and acknowledge the impact of this uncertainty on Origin customers.”
Origin said it was investigating the incident as a “matter of urgency” and that further updates will be provided “as appropriate”.
“We have notified the Australian Cyber Security Centre and the Australian Federal Police of this potential incident,” Origin said.
“We have also engaged with the Office of the Australian Information Commissioner.”
Origin provides electricity, gas, and internet to customers and businesses to 4.8 million accounts across Australia.
At this point, no threat actor has claimed responsibility for the potential incident.
Steve Hunter, Director of Engineering, APAC, at cyber security firm Arctic Wolf, said that while the incident could well have been potentially worse, the data that may have been compromised is still worrying.
"Even where credit card or banking information has not been compromised, the reported combination of contact details, dates of birth and billing history can still be extremely valuable to cybercriminals. It gives attackers the personal context needed to create convincing messages that appear to come from a trusted service provider," Hunter told Cyber Daily.
"Customers should be particularly cautious of unsolicited calls, emails or text messages referring to an overdue bill, refund, account verification or urgent password reset. They should avoid using links supplied in those messages and instead access their account through the company's official website or app."
Hunter also noted that this incident may represent a broader trend, where cybercriminals focus on "data-only extortion" without encrypting any systems.
"While the circumstances of this incident are still being investigated, organisations need to recognise that the absence of ransomware or downtime does not mean the impact is limited. Stolen customer information can be monetised and leveraged to pressure an organisation long after the initial access," Hunter said.
UPDATED 22/07/26 to add Arctic Wolf commentary.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.
David Hollingworth
David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.