0
About 900,000 Origin Energy customers affected by hack as company admits it was warned weeks before public told
The Origin Energy data hack affected 900,000 former and current customers. Photograph: Jay Kogler/AAP View image in fullscreen The Origin Energy data hack affected 900,000 former and current customers. Photograph: Jay Kogler/AAP About 900,000 Origin Energy customers affected by hack as company admits it was warned weeks before public told Chief executive, Frank Calabria, apologises and advises customers to look out for suspicious activity amid heightened scam risk Origin Energy has admitted it was warned of the hack that accessed 900,000 current and former customers’ personal data three weeks before it first made the data breach public. Australia’s largest energy retailer said a “significant” proportion of the 900,000 had been former customers, with those affected to be notified in the coming days. Origin has said the data may include customers’ names, addresses, dates of birth, phone numbers and account information, as well as the last four digits of a credit card, or the last three digits of a bank account. The company has 4.8m customer accounts in Australia, providing electricity, fossil gas, LPG and internet services to homes and businesses. Origin’s chief executive, Frank Calabria, told reporters the company was still reviewing the incident. “We are sorry,” Calabria said on Tuesday. “We don’t take for granted the trust customers place in Origin and we’re here to support them.” Calabria warned customers to watch out for suspicious activity and a heightened risk of scams. He said Origin received emails from someone claiming to have accessed customer records on 2 July. The company did not determine it was a credible threat as there was no proof of data being accessed, he said. Calabria said Origin received proof that customer data had been accessed on 22 July, last Wednesday, at which point it announced the hack. He said “historical data” appeared to have been accessed “on an unauthorised basis” and Origin had worked to secure its system to prevent similar incidents. He said the company did not believe any information had been put on the dark web. Calabria declined to answer a series of questions over when the breaches had occurred; whether Origin staff had been identified as having a role in the breach; whether a ransom had been sought, paid, or was being considered; and whether the leak risk was “live” or resolved. “It is a criminal matter which is under active investigation and, given that, we are constrained by the level of information we can provide at this time,” he said. The company last week dismissed reports it had reached a deal with its hacker to avoid data leaks, after The Australian published claims from a person claiming to be behind the hack on Friday. “Origin notes there is considerable media speculation in relation to the data security incident we are actively managing. Our investigation is ongoing, and we currently have no further updates,” an Origin spokesperson said on Friday. Explore more on these topics Australia news Ener