Origin Energy confirms data breach; hacker claims 2 million customer records held for extortion
Australia's largest energy retailer says names, addresses, birth dates and partial bank details were exposed. An unidentified hacker calling themselves 'John Doe' has threatened to leak the data within two weeks.

Key points
- Origin Energy, Australia's largest energy retailer with 4.8 million customers, confirmed a data breach exposing personal information.
- A hacker using the name "John Doe" claims to hold records on 2 million Origin customers and is demanding negotiations via the Signal messaging app.
- Exposed data includes full names, home addresses, dates of birth, phone numbers, account details, the last four digits of credit cards and the last three digits of bank accounts.
- Origin has notified the Australian Federal Police, the Australian Cyber Security Centre and the Office of the Australian Information Commissioner.
- The hacker has set up a leak site and threatens to publish the stolen data in two weeks unless Origin responds.
Origin Energy, the Australian company that supplies electricity, gas and broadband to millions of homes, has confirmed criminals broke into its systems and stole customer data.
The company has 4.8 million customers. It is still working out how many were caught up in the breach and says it will write to each affected person directly.
Origin is listed on the Australian stock exchange, brings in about $8.5 billion a year, and owns a 20% stake in UK renewable retailer Octopus. In short, it is one of the country's biggest utilities, and this is one of Australia's biggest names to be hit this year.
What was stolen?
Origin says the exposed data includes full name, home address, date of birth, phone number, account information, the last four digits of a credit card and the last three digits of a bank account.
Those partial card and bank numbers, on their own, cannot be used to move money or hijack accounts, the company said. But the full package of name, address, birthday and phone number is exactly what fraudsters use to impersonate people, open accounts in their name, or craft convincing scam calls.
| Detail | Figure |
|---|---|
| Total Origin customers | 4.8 million |
| Records the hacker claims to hold | 2 million |
| Ransom deadline claimed | Two weeks |
| Contact channel demanded | Signal messenger |
Who is behind it?
A person using the name "John Doe" contacted Australian broadcaster 7news claiming responsibility, before Origin publicly confirmed the breach. The group or individual has not been linked to any known ransomware crew.
The hacker told 7news they had tried to reach Origin's security team, customer support and board executives, and got no reply. They have now built a leak site and set a two-week clock: negotiate on Signal, or the data goes public.
This pattern, direct extortion of a company without deploying file-locking malware, has become more common through 2024. Groups like Cl0p have built entire operations around pure data theft. It is quicker, cheaper and avoids the technical mess of encrypting an energy retailer's live systems.
Origin has not said whether it plans to negotiate. Australian government guidance strongly discourages paying, and there is no evidence at this stage that a payment has been made or offered.
Should Origin customers be worried?
Yes, but the risk is fraud and scams, not direct theft from your bank account.
If you are an Origin customer, expect a rise in phishing attempts, where criminals send fake emails or texts pretending to be from Origin, your bank, or the tax office. They now have enough real detail about you to sound convincing.
A few practical steps: do not click links in unexpected messages, even if they quote your correct address or account number. Call your provider on a number you look up yourself. Consider a credit freeze through the main Australian credit bureaus if you are worried about identity fraud. Origin says it is offering a dedicated support portal to confirmed victims.
What happens next?
Origin has told the Australian Federal Police, the Australian Cyber Security Centre and the Office of the Australian Information Commissioner. CEO Frank Calabria apologised to customers and said the company is working to block further access.
The breach, first reported by BleepingComputer, lands as Australia is still absorbing the Optus and Medibank incidents of the past two years. Regulators are watching closely, and fines under the country's updated privacy laws can now run into the tens of millions.



