Hacker Claims Deal With Origin Over Data Breach
Synopsis
Origin confirmed that customer data was stolen but did not verify a hacker's claim that the breach had been privately resolved
Key Highlights
- Origin Energy disclosed that unauthorised access had compromised customer personal and limited payment information.
- A hacker claimed he made a private deal with Origin and would not leak the stolen data.
- The investigation is ongoing and Origin said it is reaching out to customers whose data was accessed.
An unauthorised hacker said to be a cybercrime group claimed it had hacked into systems used for customer care at energy retailer Origin Energy, which has now confirmed that customer data was stolen during the breach of part of its systems. The hacker said they have “negotiated a private agreement” with Origin as well and that the stolen data won’t be sold or posted online.
Customer Data Exposed
Origin stated that the breach impacted an undisclosed segment of its ecosystem and exposed the private data of some customers. The company said the data impacted may contain names, addresses, dates of birth, telephone numbers and some account information.
Origin also confirmed that the last four digits of customers’ credit cards and bank account numbers were exposed in addition to the last three of sort codes. These incomplete bits of information, it said, are insufficient to conduct purchases or access accounts.
The company, which has approximately 4.8 million customer accounts in Australia, is continuing to assess the total population of breached customers.
Origin Chief Executive Frank Calabria apologised for the incident and said it was in the process of contacting affected customers to provide support, with a dedicated contact number and resources available. The company said it does not have any more information at this time, and its investigation is ongoing.
Hacker Claims Private Deal
The individual who claimed responsibility for the attack announced to have come to a private agreement with Origin and removed a ransom countdown website. The hacker told The Australian that the situation had been resolved quietly and there would be no data leaked as a result.
The company's focus is on ensuring secure systems and preventing any more unauthorised access, Calabria said. The investigation is still going on, he said, and Origin is collaborating with independent experts in cybersecurity as well as authorities.
Claims About the Breach
The hacker, claiming to be Australian, alleged Origin sacked one of its employees whose login details were used in the breach.
The hacker also claimed to have spent almost three weeks accessing Origin’s customer management system, which is provided by Kraken, undetected before reproducing data on two million users.
The firm suffered another breach in October 2025, which it said had been carried out by an ex-employee. In March 2025, it was also among third-party victims tied to an alleged Oracle cloud data breach.
Cybersecurity Warning
According to Associate Professor Nalin Arachchilage from RMIT University, organisations lose control of stolen data once it leaves their systems. Even if the hacker assures that it will not leak, he explained that there is no way to know if copies of that data have already been shared or sold.
Arachchilage cautioned that personal information, dates of birth and account details can stay useful to cyber criminals for years because they could be used in impersonation scams. Scam safety page from Origin advises customers to be cautious of unexpected messages and verify any requests for payments or personal information.
Source: Information Age
At Inspirepreneurs Magazine, covering entrepreneurship, business failures, and the human stories behind the world's most ambitious founders. She writes at the intersection of strategy and storytelling.