Origin warns 900k customers after bank and ID details stolen

Australian energy provider Origin Energy has disclosed the full extent of a major cyber breach that has compromised the personal data of approximately 900,000 current and former customers, prompting official warnings to affected residents across the country.

The July 2 hack exposed a wide range of highly sensitive consumer information, new details confirm. While the majority of impacted customers only had basic contact and account details accessed, around 15,000 users had their government concession and scheme identification numbers stolen by unauthorized actors. An additional 60 customers had their full bank account numbers taken, and 100 more had complete identifying document information extracted from the compromised systems.

This updated count revises Origin Energy’s initial disclosure, which earlier estimated that up to 2 million of the company’s 4.2 million total customers could be impacted. In the company’s first statement following the breach, officials only confirmed that partial financial information – including the final four digits of credit cards and final three digits of bank account numbers – had been accessed. Officials note that partial financial data cannot be used to make unauthorized purchases or access customer financial accounts, but the full sensitive data compromised in the attack poses far greater risks to a smaller subset of users.

Investigations by Australian authorities have traced the origin of the cyberattack to a third-party call center based in Manila, Philippines, a revelation that came to light earlier this month.

In an official statement, Origin Energy CEO Frank Calabria said the company has made significant progress responding to the incident. “We have substantially completed our review into the information accessed for each affected customer, and our priority is completing our notifications to them and providing support,” Calabria explained. “We have taken a number of steps to enhance the security of our systems to prevent future incidents of this kind.”

To protect impacted customers, the energy provider has rolled out a suite of support measures. These include access to specialist identity theft support and cyber security services, as well as 12 months of complimentary credit monitoring for users affected by the full data compromise. Origin Energy is also urging all customers – even those not confirmed to be impacted – to stay vigilant against phishing and scam communications, regardless of whether they appear to come from Origin, financial institutions, or government agencies.

The company is advising customers to follow basic cyber security best practices, including enabling two-factor authentication on all online accounts and refusing to share personal or financial information with unsolicited contacts. “Customers should remain vigilant to any suspicious activity and to contact us directly with any questions,” Calabria added.