Can’t find what you’re looking for? Call 1300 688 648 for expert IT assistance

Cracked padlock with electricity and data streams representing the Origin Energy data breach in July 2026

In July 2026, Origin Energy confirmed that an unknown threat actor had gained unauthorised access to its systems and stolen customer data. The company serves approximately 4.8 million customer accounts across Australia, making this one of the most significant data breaches to affect Australian consumers since the Medibank and Optus incidents of 2022.

If you are an Origin Energy customer, an Australian business that holds customer data, or someone paying close attention to the pattern of large-scale breaches hitting this country, this is worth reading carefully.

What Happened in the Origin Energy Data Breach?

Origin Energy confirmed the breach in a statement to the ASX in late July 2026, after a threat actor contacted Australian media outlets claiming responsibility for the attack. The company is investigating the full scope of the incident and working with independent cybersecurity experts to secure its systems.

A person identifying as “John Doe” contacted local media outlet 7News, alleging they had accessed data belonging to around two million Origin customers. The threat actor claimed to have attempted contact with Origin’s security teams, customer support staff, and board executives without receiving a response, and set up a site threatening to publish the stolen data within two weeks unless Origin reached out to negotiate.

Origin’s Chief Executive Officer, Frank Calabria, publicly apologised to customers and confirmed the company had launched an investigation, engaged independent cyber experts, and moved to block any further unauthorised access to its systems. The company has not publicly confirmed the identity of the attacker or the precise method by which they gained entry.

What Customer Data Was Exposed?

Origin Energy has confirmed that the following categories of customer data may have been exposed in the breach.

  • Full name
  • Physical address
  • Date of birth
  • Phone number
  • Origin account information
  • Last four digits of credit card numbers
  • Last three digits of bank account numbers

Origin has emphasised that the partial financial details cannot be used to access accounts or make unauthorised transactions. Incomplete card and bank data does not give an attacker the ability to authorise purchases or hijack banking access directly.

However, cybersecurity experts have pointed out that the combination of name, address, date of birth, and partial financial data is still highly valuable to attackers. Assembled into a single customer profile, this information creates a detailed picture of an individual that can be exploited in ways that extend well beyond simple account fraud.

How Many Origin Customers Were Affected?

Origin Energy has not yet confirmed the exact number of affected customers. The company is conducting an investigation to determine which of its 4.8 million account holders had data exposed, and has committed to notifying affected individuals directly once that assessment is complete.

The threat actor who contacted media outlets claimed to hold data for approximately two million customers. Origin has not confirmed or denied this figure. The company provides electricity, natural gas, LPG, and broadband internet services across Australia, meaning the affected customer base spans a broad cross-section of the Australian population.

Which Authorities Are Investigating?

Origin Energy has notified and is actively cooperating with three separate government bodies in response to the breach.

  • The Australian Federal Police (AFP)
  • The Australian Cyber Security Centre (ACSC)
  • The Office of the Australian Information Commissioner (OAIC)

The National Office of Cyber Security is also coordinating the government’s broader response. The AFP has declined to comment publicly on whether it has identified or made contact with the individuals responsible for the breach.

The OAIC reported receiving 1,205 data breach notifications across Australia in 2025 alone, of which 716 were linked to malicious or criminal activity. The Origin Energy breach sits within an accelerating trend of large-scale attacks on Australian organisations that hold significant volumes of consumer data.

What Are the Real Risks for Affected Customers?

The incomplete financial data means direct account fraud is less likely than in some other breaches. The more significant risks come from what attackers can do with the personal information they do hold, and those risks are serious enough to warrant immediate action.

Highly Targeted Phishing Campaigns

When an attacker knows your name, address, phone number, date of birth, and that you are an Origin Energy customer, they can craft phishing messages that appear entirely convincing. Scammers may impersonate Origin representatives, government agencies, or financial institutions, referencing specific account details to build your trust and extract credentials or payments.

Identity Theft

Your date of birth and physical address are core components of identity verification across many Australian services. Combined with data obtained through separate breaches or publicly available sources, attackers can attempt to open credit accounts, redirect government correspondence, or impersonate you to service providers and financial institutions.

Physical Crimes

Cybersecurity lecturer Rumpa Dasgupta from La Trobe University warned that personalised records including physical addresses could be used to identify vulnerable properties for physical crimes such as burglary. This is a less commonly discussed consequence of data breaches, but it is a real risk that law enforcement and security researchers take seriously.

Phone Scams Targeting Known Customers

Following the Qantas breach in 2025, warnings were issued about scammers cold-calling affected customers and using known account details to build credibility. The same risk applies here. If you receive a call from someone claiming to be from Origin Energy, treat it with caution regardless of how much detail they appear to know about your account.

What Should You Do If You Are an Origin Energy Customer?

You do not need to wait for an official notification from Origin before taking protective steps. These actions are worth taking right now.

Watch for Phishing Messages

Any email, SMS, or phone call referencing your Origin Energy account should be treated with heightened suspicion in the coming weeks and months. Contact Origin directly through their official website at originenergy.com.au rather than clicking links or calling numbers provided in unsolicited messages.

Secure Your Email Account

Your email address is typically the gateway to account recovery across multiple services. Enabling multi-factor authentication on your email account significantly reduces the risk that a compromised password could lead to broader account takeovers across banking, government, and other platforms.

Check Your Credit Report

Services such as Equifax, Illion, and Experian allow Australians to access their credit report, which can flag unusual activity such as new credit applications made in your name. Checking your report now and setting up ongoing alerts gives you visibility if your data is being misused for identity fraud.

Enable Bank Transaction Alerts

Most Australian banks allow you to receive instant push notifications for any account transaction. Enabling these alerts means you will identify unusual activity quickly rather than discovering it weeks later when reviewing a statement.

Consider Placing a Credit Ban

If you are particularly concerned about identity fraud, the Australian credit reporting bodies allow individuals to place a temporary ban on credit enquiries in their name. This can prevent new credit accounts from being opened without your direct involvement, adding a meaningful layer of protection while the situation develops.

Why Does This Keep Happening to Australian Organisations?

Australia has experienced a sustained wave of significant data breaches in recent years. Medibank in 2022. Optus in 2022. Qantas in 2025. Partnered Health in July 2026. And now Origin Energy in July 2026. The pattern reflects compounding structural issues that our team encounters regularly across Australian organisations of all sizes.

Businesses are holding more customer data than ever before, often across a mix of legacy systems and modern cloud platforms. This creates a large and inconsistently secured attack surface that threat actors are skilled at probing. A poorly secured third-party supplier, a misconfigured cloud environment, or an employee account compromised through a phishing attack can all serve as entry points into what an organisation believes to be a well-protected network.

Supply chain vulnerabilities have become a particularly common vector for attacks against large organisations that believe their own infrastructure is secure. Understanding how supply chain attacks work and how to reduce your exposure is increasingly important context for any Australian business holding sensitive customer data.

The financial reward for stealing large consumer datasets continues to drive criminal investment in these attacks. And as each major breach demonstrates what Australian organisations do and do not protect, it gives future attackers more intelligence about where to look. The organisations that weather these incidents best are those that have invested in proactive security measures before an incident occurs.

What Australian Businesses Should Take From This Breach

If your organisation holds customer data, the Origin Energy breach is a direct prompt to audit your own security position honestly. The questions worth asking are whether you know exactly what data you hold and where it lives across your systems, who has access to it and whether that access is appropriate and regularly reviewed, whether you would detect an intrusion quickly, and whether your incident response plan is documented and ready to execute.

The Australian Signals Directorate’s Essential Eight remains the most practical baseline framework for Australian businesses looking to reduce their exposure to these types of attacks. Reviewing your organisation’s alignment to those controls is a sensible and immediate starting point. Find out what is replacing the Essential Eight and what it means for Australian businesses.

For professional services firms, the stakes are particularly high. Client trust is the foundation of your business model, and a breach involving client data carries consequences that extend well beyond the immediate regulatory and reputational damage. The cost of a proactive security review is a fraction of the cost of a breach investigation, mandatory OAIC notification, and the client relationships that can take years to rebuild.

If you want an honest assessment of where your business stands, book a conversation with the Otto IT team. We work with professional services firms across Australia on exactly this kind of security review, and we will tell you clearly where the gaps are and what to do about them.

Frequently Asked Questions

Has Origin Energy been hacked before?

The July 2026 breach appears to be the first publicly confirmed significant data breach directly affecting Origin Energy customers. The company has not disclosed any previous comparable incidents involving unauthorised access to customer data at this scale.

What should I do if I receive an email from Origin about the breach?

If Origin contacts you about the breach, verify the communication by navigating directly to originenergy.com.au rather than clicking any links contained in the email. Do not provide personal details in response to unsolicited contact claiming to be from Origin Energy, even if the message appears to contain information about your account.

Can the stolen data be used to access my Origin account directly?

Origin has stated that the incomplete financial data cannot be used to directly access accounts or make unauthorised transactions. However, other exposed details including your name and date of birth could potentially be used to impersonate you with Origin’s customer service team, so updating your account password and enabling any available security settings is a worthwhile step.

Is this a notifiable data breach under Australian law?

Yes. Under the Privacy Act 1988 and the Notifiable Data Breaches scheme, organisations are required to notify affected individuals and the OAIC when a breach is likely to result in serious harm. Origin has confirmed it has notified the OAIC and is in the process of contacting affected customers directly.

Does this affect Origin business customers as well as residential customers?

Origin has described the breach as affecting customer accounts broadly, which encompasses both residential and business customers across its electricity, gas, and internet service lines. If your business holds an Origin Energy account, the same protective steps outlined in this post apply to your situation.

How does this compare to the Medibank and Optus breaches?

The Medibank breach in 2022 exposed highly sensitive health information for approximately 9.7 million customers, while the Optus breach affected around 10 million people. The Origin Energy breach involves less sensitive data categories than Medibank in particular, since no health records or full financial account numbers were exposed. However, the risk profile for phishing and identity-related fraud is comparable, and the scale of the breach remains significant given Origin’s 4.8 million customer accounts.

Should my business be worried about a similar breach happening to us?

If your business holds customer personal information, you have an obligation under the Privacy Act to protect it and a practical interest in avoiding the reputational and financial consequences of a breach. The types of vulnerabilities that led to incidents like the Origin Energy breach are not exclusive to large corporations. Small and mid-sized businesses are targeted regularly, often precisely because attackers expect their defences to be weaker. Proactive security reviews and alignment to frameworks like the Essential Eight are the most effective way to reduce your risk.

managed it support articles

Related Blog Articles

Discover more insights to optimise your business with the latest IT trends and best practices. Stay ahead of the curve by learning how to leverage cutting-edge technology for success. Explore expert advice and valuable guidance to navigate the evolving world of IT solutions

Learn More