Origin Energy Breach Exposes Customer Data; Hacker Points to Offshore Weaknesses
Origin Energy confirmed a cybersecurity breach exposing names, addresses, and partial financial details of its customers. An alleged hacker claimed responsibility, citing weak security and the company’s offshoring of jobs as motivation, while the utility faces potential fines and a widening probe.
SYDNEY (The Wiregazette) – Australia’s largest energy retailer, Origin Energy, said Thursday that an unidentified hacker gained unauthorized access to customer data, including names, addresses, dates of birth, phone numbers, and account information, as well as the last four digits of credit cards and the last three digits of bank accounts. The company, which supplies electricity, natural gas, and broadband to nearly 4.7 million customers nationally, said it is still determining how many individuals were affected.
Origin chief executive Frank Calabria apologized in a statement released via the ASX. “I’m sorry this has happened. Customers trust Origin with their information, and I apologise for the impact this may cause,” he said. Calabria added that a key priority is “taking action to secure our systems and ensure no further unauthorised access.”
The company is contacting affected customers individually and has set up a dedicated support line, according to an Origin statement. Origin said it is working with the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner.
Hacker Claims and Technical Criticism
A person claiming responsibility for the breach, who uses the name Edison Walthour, told the Daily Mail that no data would be published and that the matter had been “settled” privately with Origin. The alleged hacker said they targeted Origin because the energy provider offshored customer service roles to Asia, adding that offshore agents were underpaid and that the company prioritized cost savings over security.
According to the Daily Mail, Walthour said they had accessed Origin’s customer tools for three weeks without detection before downloading data. “School projects have better security sometimes,” the alleged hacker said, describing “no company VPN, very simple passwords, everything is so readable and predictable.” Walthour claimed to have contacted Origin with the stolen information on July 2, but the company did not respond for three weeks.
The Daily Mail reported that Origin only launched an investigation after being contacted by The Australian on Wednesday, which provided a sample of 50 customer records supplied by the alleged hacker. Origin said in a statement to the Daily Mail that its investigation is ongoing and that it had “no further updates” regarding the incident.
The alleged hacker’s claim that the data of over 2 million customers was compromised has not been independently verified. Origin has not confirmed the scale of the breach, and a spokesperson on Thursday declined to say whether a ransom demand was made, according to reporting from the Sydney Morning Herald and The Age.
Regulatory and Financial Exposure
Under Australian data protection laws, Origin could face penalties of up to A$50 million, or 30% of its revenue, if it is found to have mishandled the breach or failed to secure its systems adequately, the Sydney Morning Herald reported.
Customers have been urged to monitor accounts for suspicious activity, change passwords across utility and email accounts, and remain alert for targeted phishing scams that could exploit the stolen billing histories, the same report said.
The breach adds to a string of high-profile cyber incidents in Australia. Earlier in July, healthcare provider Partnered Health reported that sensitive medical records were stolen from its national network of GP clinics. In 2025, Qantas said customer data was published by cybercriminals, and major attacks on Optus and Medibank in 2022 triggered new cyber-resilience laws in the country.
According to research from the War Studies Research Group cited by the Sydney Morning Herald, 47% of Australians experienced some form of cybercrime last year, reflecting what experts describe as escalating fatigue and anxiety among consumers.
Origin, Australia’s largest energy provider by customer count, supplies electricity, gas, LPG, solar, and internet services to nearly 5 million households and businesses. The company had previously said it did not believe credit card and bank account data was part of the breach, but confirmed on Thursday that such partial financial information was accessed. Origin noted that incomplete credit card or bank account numbers cannot be used to make purchases or access accounts.
Related articles
You might also like




