Origin Confirms Data Breach Exposing 900,000 Customer Records
Key Takeaways Australian energy provider Origin Energy has confirmed a data breach impacting approximately 900,000 current and former customers. Exposed data includes personal details, account...
Key Takeaways
- Australian energy provider Origin Energy has confirmed a data breach impacting approximately 900,000 current and former customers.
- Exposed data includes personal details, account information, and partial payment card or bank account numbers for some individuals.
- While incomplete payment details cannot be used for direct transactions, the combination of exposed data heightens the risk of phishing, impersonation, and social engineering attacks.
- Origin is collaborating with cybersecurity experts and Australian law enforcement, with the incident currently under criminal investigation.
Origin Energy Confirms Major Data Breach Affecting 900,000 Customers
Origin Energy, a prominent Australian energy provider, has disclosed that unauthorized access to its systems has resulted in a data breach, compromising the records of an estimated 900,000 current and former customers. The company confirmed the incident following an extensive internal review and ongoing forensic analysis.
Table Of Content
Frank Calabria, Origin’s CEO, issued an apology to affected customers, emphasizing the company’s commitment to providing support and assistance to those whose personal information was accessed during the incident. Origin has initiated direct communication with impacted individuals and has expanded its customer support operations, including dedicated incident response contact channels.
Timeline of the Security Incident
The energy giant first acknowledged a potential security issue on July 22, 2026. While Origin had been investigating a possible threat since early July, initial assessments did not deem the information credible. However, new intelligence surfaced on July 22, prompting the company to elevate the matter to a suspected compromise and begin precautionary customer notifications.
Scope of Exposed Customer Data
On July 23, Origin officially confirmed that an unauthorized third party had gained access to and subsequently disclosed a portion of its customer data. The compromised information may encompass customer names, residential addresses, dates of birth, telephone numbers, and Origin account details.
For a subset of customers, the breach also exposed the last four digits of credit card numbers or the final three digits of bank account numbers. Origin has clarified that these incomplete payment details are insufficient on their own to facilitate unauthorized account access or purchases. Nevertheless, the aggregation of personal identifiers and account data significantly increases the potential for targeted phishing campaigns, identity impersonation, and sophisticated social engineering tactics.
Response and Investigations
Origin is actively collaborating with independent cybersecurity and forensic specialists to contain the breach, ascertain its full extent, and fortify affected systems. The company has also engaged with key Australian government bodies, including the Australian Cyber Security Center, the National Office of Cyber Security, and the Australian Federal Police. Additionally, the Office of the Australian Information Commissioner, the nation’s privacy regulator, has been notified. Given that authorities are treating the incident as a criminal matter, Origin’s ability to publicly disclose detailed technical and operational specifics is currently restricted.
Affected customers have been offered specialized identity and cyber support services. Origin has warned all customers to remain vigilant against unexpected communications, such as calls, emails, or text messages, that claim to be from or related to their Origin account. The company advises against clicking on links in unsolicited messages and recommends independently verifying the identity of callers through official Origin contact channels. Customers are further cautioned never to share passwords, financial data, or personal information unless the requester’s identity has been unequivocally confirmed.
Origin also advocates for the implementation of two-factor authentication (2FA) on personal email accounts and other online services wherever possible. Email accounts are particularly critical, as they can often be exploited by attackers to reset passwords across multiple platforms.
Customers requiring assistance can reach out to Origin via its dedicated incident line or email. The company has committed to providing further updates as its investigation progresses.
What You Should Do
- Be Vigilant for Phishing Attempts: Exercise extreme caution with any unsolicited communications (emails, SMS, calls) claiming to be from Origin Energy. Do not click on suspicious links or download attachments.
- Verify Callers Independently: If you receive a call claiming to be from Origin and it seems suspicious, hang up and call Origin back using the official contact numbers listed on their website.
- Never Share Sensitive Information: Do not disclose passwords, full credit card numbers, or other sensitive personal or financial details unless you have absolutely confirmed the legitimacy of the request and the identity of the requester through official channels.
- Enable Two-Factor Authentication (2FA): Activate 2FA on your email accounts and any other online services that offer it. This adds a critical layer of security even if your password is compromised.
- Monitor Account Activity: Regularly review your Origin Energy account statements and other financial accounts for any unusual or unauthorized activity.
- Utilize Identity Protection Services: If offered, take advantage of any identity and cyber support services provided by Origin Energy.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.