澳大利亚最大的电力和天然气零售商Origin Energy发生重大数据泄露事件[1]。该公司拥有约480万客户[1],其中约200万客户的个人信息被盗取[1]。泄露数据包括姓名、地址、出生日期、联系电话、账户信息、信用卡末四位或银行账户末三位[1]。据报道,黑客与Origin达成协议后同意不再泄露这些数据[1]。
此次泄露凸显了网络犯罪的演变趋势。随着生成式AI技术的进步,犯罪分子可利用泄露的详细个人信息进行更有针对性的网络诈骗活动[1]。为应对这一威胁,澳大利亚联邦政府在2025年2月通过了强制性反诈骗法规,对银行、电信公司和社交媒体平台施加严格义务[1]。从2025年7月1日起,来自政府机构和合法企业的短信将在顶部显示"Verified"标记[1],以帮助用户识别可信来源。此前,澳洲四大银行因使用AI生成虚假工资单等文件的欺诈性住房贷款申请而蒙受损失,估计总值超过40亿澳元[1]。
Australia's largest electricity and gas retailer, Origin Energy, experienced a significant data breach compromising personal information belonging to approximately two million customers [1]. The company, which serves around 4.8 million customers in total [1], had sensitive data stolen including names, addresses, dates of birth, phone numbers, and partial bank account details such as the last four digits of credit cards or final three digits of bank accounts [1].
According to reports, hackers reached an agreement with Origin Energy to refrain from publicly releasing the stolen information [1]. However, the breach underscores growing cybersecurity vulnerabilities in an era where artificial intelligence advancements enable criminals to conduct increasingly sophisticated and targeted fraud schemes using detailed personal information [1]. In response to rising digital threats, Australia's federal government passed mandatory anti-scam legislation in February 2025, imposing strict obligations on banks, telecommunications companies, and social media platforms [1]. Beginning July 1, 2025, text messages from government agencies and legitimate businesses will display a "Verified" label at the top to help users distinguish authentic communications [1]. The urgency of enhanced data protection measures has been further highlighted by losses exceeding 4 billion Australian dollars sustained by Australia's four major banks from fraudulent housing loan applications involving AI-generated fake payslips and related documents [1].