An alleged hacker says Origin Energy ignored repeated emails about access to its customer database, forcing them to contact a media outlet instead.
Origin’s handling of a suspected cyberattack is under fire after a person claiming to have breached its customer database says the company ignored warnings for weeks.
The alleged hacker approached a national newspaper on Tuesday, saying Origin had failed to respond to earlier emails about the incident.
Alarm escalated only after the media outlet received a sample of 50 customer records early Wednesday and immediately forwarded them to Origin.
That timing now raises sharp questions about how a major ASX50 company identifies and escalates cyber threats.
Origin told the exchange it is investigating possible unauthorised access to customer data, while insisting it does not believe card or bank details are involved.
The company has notified the Australian Cyber Security Centre and the Australian Federal Police and says the Office of the Australian Information Commissioner is also engaged.
Origin disclosed the potential incident to the ASX on Wednesday afternoon, shortly after fielding questions from the newspaper about the alleged breach.
It currently supplies energy to about 4.8 million customers across Australia.
Details from the alleged hacker’s approach look surprisingly low-tech for a case that could rank alongside attacks on Optus, Medibank and Qantas in scale.
Contact emails were sent from a standard Gmail account, using a polite sign-off and a conventional format rather than encrypted or specialist tools.
The person claims to have written to Origin board members, security teams and customer service, saying the company had not publicly acknowledged the breach or engaged in discussions about containing it.
They also warned the data could be released publicly if Origin failed to respond, framing their outreach as an attempt to resolve the issue beforehand.
That version of events, if accurate, suggests a gap between how threats are reported to Origin and how they are acted on internally.
Cybersecurity experts say the episode highlights how large listed companies can still appear flat-footed when dealing with fast-moving data threats.
Origin’s apparent reliance on a journalist’s query to trigger a formal ASX announcement looks like a governance and incident-response problem, not just a technical one.
The case also underlines the growing expectation that major utilities must react swiftly and transparently to any suggestion of customer data exposure.
How Origin documents these early contacts and explains its triage process now looks central to restoring confidence in its cyber defences.

