News

Alleged Hacker Claims Private Settlement With Origin Energy Following Major Data Breach

An alleged hacker who threatened to publish the personal information of millions of Origin Energy customers says the dispute has been resolved privately, although the energy retailer has not confirmed that a settlement was reached.

Origin Energy is continuing to investigate a serious cybersecurity incident after confirming that an unauthorised party accessed and disclosed some customer information.

The individual claiming responsibility, who has used the name Edison Walthour, had threatened to publish the allegedly stolen information within 14 days. The person later told The Australian that the threat had been withdrawn following private discussions with Origin.

“We took our site down, we already settled everything with Origin Energy privately and no data will be leaked,” the alleged hacker said.

Origin has not publicly confirmed any agreement.

“Origin notes there is considerable media speculation in relation to the data security incident we are actively managing. Our investigation is ongoing, and we currently have no further updates,” an Origin spokeswoman said.

Millions of customer records allegedly accessed

The alleged attacker claimed to have obtained information connected to approximately two million Origin customers.

The data was said to include customer names, dates of birth, telephone numbers and billing histories. The compromised records also allegedly contained incomplete financial details, including the final four digits of some credit card numbers and the final three digits of some bank account numbers.

Origin initially said it did not believe credit card or banking information had been accessed. The company later confirmed in a statement to the Australian Securities Exchange that some partial payment information was included in the affected data.

Origin chief executive Frank Calabria apologised to customers following the disclosure.

“I’m sorry this has happened,” he said.

The company notified the Australian Federal Police, federal cybersecurity authorities, privacy regulators and the ASX after receiving a sample containing approximately 50 purported customer records.

Employee credentials allegedly used to enter system

The suspected hacker claimed that access was obtained through an employee account connected to Origin’s customer management system, which is supplied by energy technology company Kraken.

According to the individual, the account provided access to customer tools for approximately three weeks before the activity was detected.

The alleged attacker criticised Origin’s security arrangements, claiming that simple passwords, predictable systems and the absence of a company virtual private network made it easier to gain access.

These claims have not been independently verified. Origin declined to comment on an additional allegation that the employee whose credentials were used had been dismissed.

The incident highlights the risks associated with compromised employee accounts. Even when organisations invest in sophisticated security platforms, weak passwords, excessive account permissions and inadequate monitoring can provide attackers with a path into sensitive systems.

Motivation linked to offshoring concerns

The alleged hacker identified themselves as Australian and claimed the attack was motivated by concerns about Origin’s use of offshore customer service providers.

Origin operates a hybrid customer support model, with employees in Australia and service providers in Manila, the Philippines. The company completed two rounds of redundancies connected to its offshoring strategy last year.

The person claiming responsibility said the attack was intended to draw attention to the treatment of overseas workers and what they described as Origin’s focus on reducing costs.

Regardless of the stated motivation, accessing or disclosing customer information without authorisation can cause considerable harm. Victims may face phishing attempts, identity theft, account takeover and financial fraud long after the original incident has been contained.

Investigation remains active

Origin has confirmed that unauthorised access and disclosure occurred, but the full scale of the incident remains under investigation.

The alleged hacker’s statement that the matter has been privately settled does not establish whether the data has been deleted, copied, transferred to another party or retained elsewhere. Until the investigation is completed, affected customers should remain alert to suspicious emails, telephone calls, text messages and unexpected account activity.

Customers should avoid sharing passwords or verification codes with anyone claiming to represent Origin. They should also use unique passwords, activate multifactor authentication where available and contact Origin through official channels if they receive an unusual request.

Australian organisations can face substantial penalties for serious failures involving personal information. Beyond regulatory consequences, breaches of this scale can damage customer trust, disrupt operations and expose weaknesses in access controls, employee training and incident response processes.

Cybersecurity starts with informed people

Technology alone cannot prevent every cyberattack. Employees and business leaders must be able to recognise suspicious behaviour, protect credentials, report security incidents and understand how attackers exploit everyday mistakes.

The Origin incident should serve as a reminder for organisations of every size to strengthen the human side of their cybersecurity defences.

Improve your cybersecurity knowledge by taking The Hack Academy’s online training programme. The training can help you develop greater awareness of cyber threats and make safer decisions when handling passwords, accounts, messages and sensitive information. Enrol with The Hack Academy and take a practical step towards protecting yourself, your customers and your organisation.

Leave a Reply

Your email address will not be published. Required fields are marked *