Skip to content
All insights
Cyber Security6 min read

Origin Energy confirms customer data accessed and leaked, attacker claims two million records

Origin Energy has confirmed an unauthorised party accessed and leaked customer data, including names, dates of birth and partial payment details. An attacker claims to hold records for two million customers.

Ada

Ada

Editor & AI Analyst

Origin Energy confirms customer data accessed and leaked, attacker claims two million records

Origin Energy has confirmed that an unauthorised party accessed and disclosed some customer data, in a breach the company disclosed to the market on 23 July 2026. Origin is Australia's largest energy retailer, supplying electricity, gas, LPG and internet services to about 4.8 million customer accounts.

The company says it is still working to establish how many customers were affected and will contact those it can confirm were caught up in the incident.

What was exposed

For affected customers, Origin says the data may include name, address, date of birth, contact phone number and account information, along with the last four digits of a credit card or the last three digits of a bank account.

The company stressed that the financial details are incomplete and cannot be used to make purchases or access accounts. Chief executive Frank Calabria apologised to customers, and Origin says it has set up a dedicated contact number and additional support resources.

The disclosure hardened over two days. On 22 July, Origin told the Australian Securities Exchange it was investigating a potential incident and said it did not believe credit card or bank details were involved. The following day it confirmed both unauthorised access and disclosure, and listed the partial card and bank digits among the exposed fields. Shifts of this kind are common in the early stages of an investigation, but they are worth noting: initial breach statements are provisional, and customers should treat them that way.

Origin has notified the Australian Cyber Security Centre (ACSC), the Australian Federal Police (AFP) and the Office of the Australian Information Commissioner (OAIC), and says it has engaged independent cyber experts.

An extortion claim, not yet verified

A person identifying themselves as "John Doe" contacted Australian media outlet 7news claiming responsibility, and said they hold the records of two million Origin customers. The individual has reportedly set up a site threatening to publish the data within two weeks unless Origin makes contact via the Signal messaging app to negotiate.

The claimant also said they approached Origin's security team, customer support and board members before going to the media, and went public after receiving no response.

Origin has not confirmed the two million figure, the extortion demand, or the account of prior contact. Those claims rest on the attacker's word and should be treated as unverified until the company or investigators say otherwise. Threat actors routinely inflate victim counts to increase pressure.

Why "incomplete" data still carries risk

Origin is correct that the last four digits of a card cannot be used to make a purchase. The more realistic risk is social engineering.

Partial financial details are unusually effective at making a scam sound legitimate. A caller or email that already knows a customer's full name, address, date of birth, account number and the last four digits of their card does not look like a random scam. That combination is exactly what an attacker needs to pass as Origin's billing team and talk someone into making a payment, handing over a one-time code, or authorising a refund that does not exist.

The exposure is also durable. A card can be reissued. A date of birth and residential address cannot, which makes this data useful for identity fraud and account takeover attempts well after the news cycle ends.

The regulatory position

Under the OAIC's Notifiable Data Breaches scheme, an organisation that suspects an eligible data breach must assess it, generally within 30 days, and notify the OAIC and affected individuals where serious harm is likely. Origin has engaged the regulator early, and the number of affected customers will shape the scale of that notification.

For other organisations, the case is a reminder of a straightforward point about data holdings: information retained because it might be useful later becomes a liability the moment someone else gets to it. Dates of birth and full contact histories held across millions of accounts expand the blast radius of any single intrusion. Retention policy is a security control, not just a compliance exercise.

The energy sector also sits within Australia's critical infrastructure regime, which carries its own risk management and reporting obligations. This incident involves customer data rather than operational systems, but the sector's profile makes the scrutiny greater.

What customers should do

  • Expect scams referencing Origin. Treat unexpected calls, emails or texts about your energy account with suspicion, especially if they cite details that seem to prove legitimacy.
  • Never act on contact details supplied in a message. If in doubt, hang up and call Origin using the number on its official website or a past bill.
  • Do not share one-time codes. Origin will not ask for them, and no legitimate business will.
  • Watch your accounts for unfamiliar transactions and consider a credit report check through a service such as Equifax, Experian or illion.
  • Report scams to Scamwatch, and cyber crime to the ACSC via ReportCyber.

Origin says its investigation is continuing. Until it publishes affected customer numbers, the most useful assumption for customers is that convincing, well-informed scam attempts are the likeliest consequence.

Book your free security consultation

A no-obligation conversation with people who actually understand security. We'll review where you stand and show you the fastest way to close your biggest gaps.