Major thing 4.8 million Aussies must do after Origin Energy hack

One of Australia’s largest utility providers, Origin Energy, has confirmed a major cybersecurity incident that has put the personal information of millions of its customers at risk, prompting urgent warnings for heightened scam awareness across the country. The unfolding breach, which was first flagged to the public last Wednesday, took a serious turn on Thursday when company executives confirmed that unauthorized actors had successfully accessed internal systems and stolen sensitive customer data.

Initial media reports from *The Australian*, citing correspondence with the alleged perpetrator, claimed that roughly two million customer accounts had been compromised. To date, Origin Energy has not issued a confirmed number of affected accounts, out of its total 4.8 million residential and commercial customer base. According to the company’s official disclosure, the compromised data can include full names, residential addresses, dates of birth, contact telephone numbers, detailed account information, partial credit card numbers (only the final four digits), and partial bank account details (only the final three digits). Company officials have stressed that the incomplete financial information stolen cannot be used directly to make unauthorized purchases or access customer bank accounts, but that does not eliminate the long-term risk posed by the breach.

Cybersecurity experts warn that the stolen data creates a perfect breeding ground for sophisticated targeted scams. Tyler McGee, head of Asia-Pacific operations for global cybersecurity firm McAfee, who himself received a breach warning from Origin, noted that scammers routinely leverage high-profile data breaches to exploit consumer trust. “Until there is full clarity around the scope of the breach, it is impossible to know exactly how exposed impacted consumers are, but the core fact remains: any stolen personal information allows scammers to craft more convincing targeted scams, either for their own use or to sell on to other criminal actors,” McGee explained. Stolen personal details let scammers create messages that reference specific personal information, making fraudulent communications appear legitimate, as if they came from Origin or another trusted business the customer interacts with regularly. For criminal groups, McGee added, this is a numbers game: even if only a tiny fraction of targets fall for the scam, the operation turns a profit.

New details that emerged on Friday paint a clearer picture of the alleged perpetrator. *The Australian* reported that the hacker, who uses the online alias Edison Walhour, claims to be an Australian former Origin employee. The individual reportedly used a valid former employee login to access Origin’s customer management system, which is provided by third-party vendor Kraken. In a surprising development, the hacker has reportedly backed away from their initial threat to auction the full stolen dataset on public dark web marketplaces. It remains unclear what prompted this change of plans.

In response to the incident, McGee has outlined clear steps Origin customers can take to protect themselves from subsequent scams. First, he advised all potentially impacted customers to update their online account passwords immediately and enable two-factor authentication wherever possible to block unauthorized access. Second, customers should exercise extreme caution around any unsolicited emails, text messages, or phone calls that ask them to click links, share personal information, or make payments. “Consumers need to maintain a heightened state of awareness for the foreseeable future, and anyone looking for extra protection should consider investing in commercial scam protection tools,” McGee added. He also noted that once personal data is leaked by criminals, it remains in circulation permanently, creating ongoing risk for affected individuals.

McGee also pointed out that Australian companies are disproportionately targeted by hackers for two key structural reasons. Historically, Australian corporations have been more willing to pay large ransom demands to end breaches quickly, making them attractive targets. Additionally, Australian law enforcement has far limited capacity to pursue hackers based outside of the country, unlike jurisdictions such as the United States, which routinely works with international partners to extradite cybercriminals for prosecution.

Origin Energy chief executive Frank Calabria has issued a formal apology to customers affected by the incident. “I am sorry this has happened. Customers trust Origin with their personal information, and I apologize for the stress and impact this may cause,” Calabria said. The company is currently working alongside independent cybersecurity experts and law enforcement authorities to investigate the breach, secure its systems, and mitigate further risk to customers.

As the investigation continues, authorities and cybersecurity professionals are urging all 4.8 million Origin customers to remain alert to scam activity in the coming months, regardless of whether they have been formally notified that their data was compromised.