Origin Energy data breach affected 900,000 customers
The news: About 900,000 current and former Origin Energy customers had their information accessed in a data breach that was announced to the exchange last week.
The context: CEO Frank Calabria said in a statement that the energy company had “completed the initial phase” of its review into the “customer data security incident”.
Calabria said Origin had been reviewing a potential security threat since early July but “it was not assessed to be credible”. However, additional information emerged on 22 July that “indicated a potential security incident may have occurred”.
Calabria also said the amount of information that can be disclosed is limited because the incident is “criminal matter” subject to an ongoing investigation by relevant authorities.
The company is working “very closely” with the Australian government and agencies including the Australian cybersecurity Centre, the National Office of Cybersecurity and the Australian Federal Police. The Office of the Australian Information Commissioner has been notified.
Origin’s review of the incident is also ongoing.
The company is in the midst of contacting affected customers, having extended customer support hours and established a dedicated contact number relating to the incident. Calabria also said that Origin is working with “cybersecurity and forensic specialists to ensure the incident is contained” and has taken steps to secure company systems.
What they said: “To our customers, I am sorry. We don’t take for granted the trust customers place in Origin and our safeguarding of their information,” Calabria said.
The source: Origin Energy media statement