When a company that holds the intimate details of nearly a million lives learns those details have been taken, the clock that matters most is not the one tracking the investigation — it is the one measuring how long ordinary people remain unaware of their own vulnerability. Origin Energy, Australia's largest energy retailer, has acknowledged a three-week silence between receiving a credible warning of a data breach and telling the 900,000 customers whose names, addresses, and financial fragments were exposed. The apology has now been offered, but the questions it was meant to answer remain, by
Origin Energy admits 3-week delay in disclosing hack affecting 900,000 customers
We are sorry. We don't take for granted the trust customers place in Origin.
Why did Origin wait three weeks to tell customers about the breach?
They say they didn't have proof until July 22. Someone claimed to have the data on July 2, but Origin didn't believe it was real without evidence. Once they had that evidence, they went public the same day.
That still feels like a long time for customers to be exposed without knowing.
It is. And the company won't explain what happened during those twenty days between the initial warning and the proof. That's the gap that matters most.
What exactly was stolen?
Names, addresses, birth dates, phone numbers, account information. For some people, the last few digits of credit cards or bank accounts. Enough to commit identity theft or fraud.
Did the company pay the hackers?
Calabria wouldn't say. He wouldn't answer whether a ransom was demanded, paid, or even being considered. He cited the criminal investigation.
So customers are left in the dark about whether the threat is over?
Exactly. He said he doesn't believe the data made it to the dark web, but he wouldn't confirm the risk is resolved. For 900,000 people, that's a significant thing not to know.
What does Origin want customers to do now?
Watch for suspicious activity. Be alert to scams. But without knowing the full scope of what happened, it's hard to know what precautions are actually enough.
Il Polso
- Nine hundred thousand current and former customers had personal and partial financial data stolen, leaving them exposed to identity theft and targeted scams without their knowledge for weeks.
- Origin Energy sat on credible evidence of the breach for three weeks before going public, a delay that has drawn sharp scrutiny over whether corporate caution was prioritised over customer safety.
- The CEO appeared before reporters to apologise but refused to answer whether staff were involved, whether a ransom was paid, when the breach actually occurred, or whether the data leak risk is still active.
- Origin insists the data has not appeared on the dark web, yet will not confirm the threat has passed — leaving affected customers to weigh a reassurance the company itself cannot fully stand behind.
- The company is now in the process of notifying all 900,000 affected individuals, a disclosure that arrives weeks after the danger first became known inside its own walls.
When a company that holds the intimate details of nearly a million lives learns those details have been taken, the clock that matters most is not the one tracking the investigation — it is the one measuring how long ordinary people remain unaware of their own vulnerability. Origin Energy, Australia's largest energy retailer, has acknowledged a three-week silence between receiving a credible warning of a data breach and telling the 900,000 customers whose names, addresses, and financial fragments were exposed. The apology has now been offered, but the questions it was meant to answer remain, by the company's own choice, unanswered.
Origin Energy, Australia's largest energy retailer serving 4.8 million accounts, has admitted to a three-week gap between learning of a customer data breach and informing the public. Chief executive Frank Calabria appeared before reporters to apologise, confirming that 900,000 current and former customers had personal information compromised — including names, addresses, dates of birth, phone numbers, account details, and for some, the last digits of credit card or bank account numbers.
The timeline Origin offered raises difficult questions. On July 2, the company received emails claiming hackers had accessed customer records, but dismissed them as unverified. It was not until July 22 — twenty days later — that proof arrived, and Origin disclosed the breach publicly that same day. During those three weeks, customers whose data was already in criminal hands had no way of knowing to protect themselves.
When pressed on the details that matter most — when the breach actually happened, whether any staff were involved, whether a ransom was demanded or paid, and whether the data remains at risk of being published — Calabria declined to answer, citing an ongoing criminal investigation. The company had previously denied negotiating with hackers, but offered no further clarity. Origin said it does not believe the data has appeared on the dark web, but would not confirm the danger has passed.
The gap between the company's public apology and its refusal to answer basic questions is difficult to reconcile. Origin said it would notify all affected customers in the coming days — a process that, for many, will be the first they hear of a risk that has existed for weeks already.
Origin Energy, Australia's largest energy retailer, has acknowledged a three-week gap between learning that hackers had accessed customer data and telling the public about it. The company serves 4.8 million customer accounts across the country, providing electricity, gas, LPG, and internet services. On Tuesday, chief executive Frank Calabria stood before reporters to apologize and explain what had happened—or at least, what the company was willing to say.
Nine hundred thousand current and former customers had their personal information compromised. The breach exposed names, addresses, dates of birth, phone numbers, and account details. For some customers, the last four digits of a credit card or the last three digits of a bank account number were also taken. Calabria warned people to watch for suspicious activity and scams, acknowledging the heightened risk that comes with having such information in the hands of criminals.
The timeline Origin provided raises uncomfortable questions about how the company handled the threat. On July 2, someone sent emails claiming to have accessed customer records. Origin did not treat this as credible at the time, saying there was no proof that data had actually been stolen. Twenty days later, on July 22, the company received evidence that the breach was real. That same day, Origin announced it publicly. The three-week delay between the initial warning and the proof of access—and the subsequent public disclosure—means customers were potentially at risk without knowing it.
When asked about the specifics, Calabria declined to answer. He would not say when the actual breach occurred, whether any Origin staff members were involved, whether a ransom had been demanded or paid, or whether the threat was still active. He cited the ongoing criminal investigation as the reason for the silence. The company had previously dismissed reports that it had negotiated with hackers to prevent the data from being leaked online, but Calabria offered no clarity on that front either. He said Origin did not believe any information had been posted to the dark web, but he would not confirm whether that risk had passed.
The company's reluctance to answer straightforward questions about the breach sits uneasily with its public apology. Calabria said Origin did not take for granted the trust customers placed in it and was there to support them. Yet the company's own actions—waiting three weeks to disclose the breach, refusing to answer basic questions about what happened—suggest a more cautious approach to transparency. A significant portion of the 900,000 affected customers are former clients, and Origin said it would notify everyone in the coming days. What happens next depends partly on information the company has chosen not to share.
Citazioni salienti
We are sorry. We don't take for granted the trust customers place in Origin and we're here to support them.— Frank Calabria, Origin Energy CEO
It is a criminal matter which is under active investigation and, given that, we are constrained by the level of information we can provide at this time.— Frank Calabria, on why he declined to answer questions about breach details