Energy One takes systems offline after cyberattack on Australian and UK operations

Organization
Energy One
Exploit
Hacking
Industry
Energy Software

Energy One, an Australian listed supplier of software and services to the wholesale energy market, disclosed a cyberattack that affected corporate systems in both Australia and the United Kingdom. The company said it detected the incident on August 18, 2023 and announced it publicly on August 21.

As a containment step, Energy One disabled some of the links between its corporate systems and the customer-facing systems used by energy retailers, generators and traders across Australasia, the United Kingdom and Europe. The company said it had taken immediate action to limit the impact of the intrusion.

Energy One engaged the cybersecurity firm CyberCX and alerted the Australian Cyber Security Centre along with certain UK authorities. It said its investigation was focused on identifying the initial point of entry, determining whether any additional systems had been affected, and establishing whether personal information or customer-facing systems had been compromised.

The company did not identify the attackers or the method used, and no group publicly claimed responsibility. Because Energy One's software underpins trading operations for wholesale energy customers, including UK companies, the incident drew attention from critical infrastructure observers. The investigation remained open as of the reporting date, with no confirmed data theft announced.

Sources