Origin apologises after revealing 900,000 customers affected by data breach

In Brief

  • Origin says 900,000 customers were affected by a data breach.
  • It’s advising customers to be wary of a heightened risk of scammers.

Almost one million Origin Energy customers had their details accessed by hackers after a major data breach last week, the company has revealed.

On Tuesday, Origin said it had completed an initial review into the incident and identified that approximately 900,000 current and former customers’ data was accessed by the hackers.

“To our customers, I am sorry. We don’t take for granted the trust customers place in Origin and our safeguarding of their information,” CEO Frank Calabria said in a statement.

Last week, the energy company announced it was the victim of the security incident, saying names, addresses, dates of birth, phone numbers and account information could all have been viewed.

Other potential details include the last four digits of credit cards, or the last three digits of bank accounts.

Your trusted source for staying up-to-date with the world around you. Get free daily news updates and analysis, straight to your inbox.

The company said it would be contacting affected customers first and was opening up a dedicated hotline for those concerned.

Origin said it had been trying to confirm the credibility of the threat since early July.

“We worked to confirm its credibility and potential impact; however, based on the information available, it was not assessed to be credible,” Calabria said.

“On 22 July, new information emerged that indicated a potential security incident may have occurred. We acted immediately, providing updates to the market and notifying our customers as a precaution.”

Origin, which has 4.8 million customer accounts in Australia and provides electricity, natural gas, LPG and internet services, said last week it did not believe the data obtained included credit card or bank details.

Customers advised to be wary of scams

The company has also warned customers to be alert to a greater risk of scams that could arise from the data breach, advising customers to be wary of unexpected calls, emails or texts referring to their account.

Those who get such contact should independently contact Origin through numbers on official channels, it said, and do not provide passwords or personal information to anyone.

“We are acutely aware that others may exploit this incident, including by impersonating Origin or through other scam activity,” Calabria said.

“We recommend that all our customers remain vigilant to suspicious activity and a heightened risk of scams.

Griffith University’s Graeme Hughes, an expert on business and consumer issues, said the breach was unlikely to cause cases of payment fraud but marked a “social engineering problem”.

“The last four digits for a card, a date of birth, and an authentic billing history are the exact trust signals a business uses to verify itself over the phone,” Hughes told the Australian Associated Press.

“That makes an unsolicited call about an energy account far more convincing than it should be.

— With additional reporting by the Australian Associated Press.


For the latest from SBS News, download our app and subscribe to our newsletter.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *