Origin Energy has revealed full bank account numbers belonging to about 60 customers were accessed during its July data breach, along with around 100 ID document numbers.
The Australian gas and electricity retailer first announced it was investigating a potential data breach involving unauthorised access to “some customers’ data”.
Within a week, Origin confirmed that information belonging to approximately 900,000 current and former customers had been accessed.
The company has now completed a review to determine exactly what information was accessed for each affected customer.
While customers were initially told that credit card and bank details were not included in the breach, Origin confirmed on Friday that the full bank account numbers of approximately 60 customers had been accessed.
“Customers should remain vigilant to any suspicious activity and to contact us directly with any questions,” said Origin chief executive Frank Calabria.
Around 100 customers also had an “ID document number” compromised, while roughly 15,000 customers had “numbers associated with government concession scheme or programs” exposed.
Origin stressed that while these numbers were exposed, no scanned copies of related ID documents or cards were affected.
“We have substantially completed our review into the information accessed for each affected customer, and our priority is completing our notifications to them and providing support,” Calabria said.
The bulk of the damages
For most of the approximately 900,000 persons affected, the compromised information included some combination of their name, address, date of birth, phone number and account information.
Customers may have also had “other information” about personal circumstances they’d shared with Origin accessed, as well as the last four digits of a credit card or the last three digits of a bank account.
In some cases, limited details of third party contacts listed on a customer’s account were also accessed.
When asked how long Origin had held onto the data of former customers impacted by the breach, a spokesperson told Information Age that Origin retains customer records in line with applicable laws.
“We delete in accordance with these applicable laws,” they told Information Age in early August.
“We don't hold onto information longer than we're required or permitted to.”
Hack traced to the Philippines
Origin’s latest update comes as authorities reportedly investigate a suspected link between the breach and a call centre in Manila, the Philippines.
Investigators linked the hack to a former Manila-based employee of Accenture – a consulting firm that helps Origin operate its call centres – according to the Australian Financial Review.
The former employee is alleged to have intended to extort Origin in exchange for the compromised data, although this had not been proven at the time of writing.
A hacker who claimed responsibility for the breach previously told media outlets they had reached an agreement with Origin and would not leak any of the data on the dark web.
Information Age understands Origin’s compromised data had not been publicly leaked at the time of writing.
Origin confident in its response
On Friday, Calabria said although a criminal investigation was ongoing, Origin was “confident in the steps we have taken to respond”.
The company said it had strengthened the security of its systems to help “prevent future incidents of this kind”.
Origin also confirmed it has contacted the approximate 900,000 persons impacted and “provided them with support”, including identity monitoring and 12 months of free credit monitoring.
Origin’s latest annual report meanwhile confirmed Origin’s executive managers would see their bonuses slashed as a result of the data breach.
Calabria’s pay was reduced by $357,000, while other executive management collectively lost $607,000.
“Executive management is taking a shared accountability for the occurrence of the incident,” read the report.
“The board has determined that it is appropriate for proximate remuneration adjustments to be made to FY26 incentive outcomes to reflect that shared accountability.”
Origin said it continues to work closely with the Australian government and other agencies, including the Australian Cyber Security Centre, the National Office of Cyber Security and the Australian Federal Police.