Origin Energy Reveals Bank Account Data Exposed in 900,000-Customer Breach
Synopsis
The company said attackers accessed full bank account numbers belonging to around 60 customers and about 100 ID document numbers after unauthorised access to customer data was discovered in July, affecting some 900,000 current and former customers.
Origin Energy has revealed that bank account numbers belonging to about 60 customers were accessed during its July data breach, adding to the scope of an incident that affected information linked to roughly 900,000 current and former customers.
The energy retailer initially said some customer data had been accessed without authorisation. It has since completed a detailed review of the information involved.
Around 100 customers had an ID document number exposed while approximately 15,000 had numbers linked to government concession schemes or programs accessed.
Origin said no scanned copies of identity documents or cards were compromised. It also stressed that most affected customers had information such as names, addresses, dates of birth, phone numbers and account details exposed.
Origin Strengthens Support for Affected Customers
Origin’s Chief Executive Frank Calabria said the company had substantially completed its review and was focused on notifying affected customers and providing support.
The company has contacted to approximately 900,000 people affected and offered measures including identity monitoring and 12 months of free credit monitoring.
For some customers, the exposed information also included details they had shared about their personal circumstances. Limited information relating to third-party contacts on customer accounts may also have been accessed.
Origin said it retains customer records in line with applicable laws and does not keep information longer than it is required or permitted to. The company has also strengthened its systems following the incident and said it remains confident in its response.
Investigation Points to Suspected Offshore Link
The breach is also being investigated by Australian authorities with reports pointing to a suspected connection to a former Manila-based employee of Accenture which helps Origin operate its call centres.
The former employee has reportedly been linked to the compromised data and is alleged to have sought to extort Origin. The allegation has not been proven.
Origin said it continues to cooperate with government agencies including the Australian Cyber Security Centre, National Office of Cyber Security and Australian Federal Police.
The breach has also had consequences for Origin's senior leadership. Its annual report revealed that executive remuneration was reduced because of the incident. Calabria's pay was cut by $357,000 while other members of executive management collectively lost $607,000.
Origin said the adjustments reflected shared accountability for the security incident. The incident added another financial consequence to one of Australia's largest recent customer data breaches.
Source: Information Age
Vishal is an experienced Editor at Inspirepreneur Magazine with key interests in artificial intelligence, eCommerce, entrepreneurship, lifestyle and startup sector. Prior to joining Inspirepreneur, he was a Content Writer cum Correspondent at Siliconindia Magazine, where he worked on Company Profiles, Cover Stories, Executive Profiles, Feature Articles and Thought Leadership content.
You Might Also Like
The Irreplaceable Value of Human Leadership in the Age of AI
What Are the Benefits of Self-Reflection and How Can It Transform Your Life?