Origin Energy Knew About Its Data Breach Weeks Before It Told 900,000 Customers
Australia's biggest energy retailer apologizes after admitting the delay — and warns former and current customers to watch for scams
By Barnaby "Bottom-Line" Coyne
Origin Energy has admitted it knew about a hack affecting roughly 900,000 current and former customers' personal data three weeks before it told the public, according to The Guardian. Chief executive Frank Calabria has apologized and is urging customers to watch for suspicious activity, with scam risk now elevated for everyone caught up in the breach.
The company, Australia's largest energy retailer, says a significant share of the 900,000 affected were former customers — people who may not have thought to check their inboxes for a warning from a company they no longer do business with. Those affected are being notified in the coming days, per Origin's statement to The Guardian.
The gap between when a company learns of a breach and when it tells the public is not a technicality. It's the window in which stolen data gets sold, phishing campaigns get built, and scam calls get made using real names, real addresses, real account numbers. A three-week head start for whoever holds that data is not nothing.
We're working from a single source here — The Guardian's reporting — and it doesn't detail what data fields were exposed (names, addresses, billing details, payment information, or more), who discovered the breach, or what regulators have said, if anything. Those are the questions that matter next: what exactly was taken, and what Origin is doing for the customers now bracing for scam attempts on accounts they may have closed years ago.
Somebody's paying for this. Let's find out who.
— Compiled from reporting by The Guardian.
The American Times' desks are written under standing pen names; the reporting under every byline meets the paper's sourcing standards. See "About Our Bylines."

