Australian energy retailer Origin Energy has launched an investigation into a potential data breach after receiving notification from one of its third-party service providers that customer information may have been accessed without authorisation.
The company said the incident did not involve Origin's own internal systems, but instead relates to an external technology provider used to manage some customer services. Initial investigations indicate that the personal information of up to two million current and former customers may have been exposed.
According to Origin, the compromised information may include customer names, contact details, dates of birth and account-related information. At this stage, the company said there is no evidence that financial information such as bank account details, passwords or payment card information has been compromised. The scope of the incident remains under investigation.
Origin said it acted immediately after becoming aware of the incident by activating its cyber security response procedures. The company is working closely with the third-party supplier, cyber security specialists and relevant government agencies to determine exactly what information was accessed and which customers may have been affected.
The company has also notified the Office of the Australian Information Commissioner (OAIC) and the Australian Cyber Security Centre (ACSC), in line with Australia's mandatory data breach notification requirements. Regulatory authorities are expected to monitor the investigation as it progresses.
Origin Energy said customers who are confirmed to be affected will be contacted directly with information about the incident and advice on how to protect themselves. The company is encouraging customers to remain alert for suspicious emails, text messages or phone calls claiming to be from Origin or other organisations requesting personal information.
Cyber security experts generally recommend that affected individuals monitor their accounts for unusual activity, be cautious of phishing attempts, avoid clicking on unexpected links, and use strong, unique passwords together with multi-factor authentication wherever available.
The incident comes amid increasing cyber attacks targeting Australian businesses and organisations. Over recent years, several major Australian companies have experienced large-scale data breaches, prompting increased investment in cyber security and stronger regulatory requirements designed to protect consumer information.
Origin emphasised that the investigation is ongoing and that the company is continuing to assess the extent of the incident. Further updates will be provided as more information becomes available.
The company apologised to customers for the concern caused and said protecting customer information remains a priority. It also stated that it is reviewing security arrangements with external service providers to reduce the risk of similar incidents in the future.
While investigators continue to determine exactly what data may have been accessed, Origin has urged customers to stay vigilant and report any suspicious communications that appear to misuse the company's name or branding.











