Breach Confirmed
Origin Energy, Australia's largest energy retailer serving approximately 4.8 million customers, has confirmed that an unauthorized third party accessed and subsequently leaked customer data online. The breach exposes sensitive personally identifiable information (PII) and, in some cases, partial financial data.
A threat actor identifying as "John Doe" contacted Australian outlet 7News prior to the company's official disclosure, claiming to hold data for roughly 2 million Origin customers. Origin has since confirmed the incident and is conducting individual impact assessments to determine the full scope.
What Was Exposed
| Data Type | Exposed |
|---|---|
| Full names | Yes |
| Home addresses | Yes |
| Phone numbers | Yes |
| Account details | Yes |
| Partial credit card / bank account numbers | Yes (last few digits) |
| Passwords or full payment credentials | Not confirmed |
Origin initially stated that financial data was "not expected" to be affected. That position was subsequently revised as the investigation revealed partial payment data — specifically the last few digits of credit card and bank account numbers — was included in the leaked dataset.
Timeline and Response
- Pre-disclosure: Threat actor contacted 7News with a sample of data before Origin's public statement
- Breach confirmed: Origin publicly confirmed unauthorized access on July 23, 2026
- CEO statement: Origin CEO Frank Calabria issued a public apology acknowledging the incident
- Authorities engaged: Australian Federal Police (AFP) notified; Australian Cyber Security Centre (ACSC) contacted; Office of the Australian Information Commissioner (OAIC) notified as required under the Privacy Act 1988
- Systems secured: Origin states systems have been secured following discovery
- Customer support: A dedicated support portal launched for affected customers pending impact assessment completion
Why This Matters
Compounding Fraud Risk
Partial payment data combined with full PII creates a meaningful fraud vector. Armed with a customer's full name, address, phone number, and partial card digits, attackers can:
- Conduct targeted phishing and smishing with high credibility (attackers can confirm they "know" partial account details to establish legitimacy)
- Attempt social engineering against financial institutions using the partial card data as a verification bypass
- Build enriched identity profiles by combining this breach with other publicly available data
Critical Infrastructure Exposure
As Australia's largest energy provider, Origin's customer base represents a significant cross-section of the Australian population. The breadth of this breach — potentially reaching 2 million people — places it among the larger Australian data incidents in recent years, following previous high-profile breaches at Optus (2022) and Medibank (2022).
Regulatory Implications
Under Australia's Notifiable Data Breaches (NDB) scheme, Origin is obligated to notify the OAIC and affected individuals. With partial financial data involved, the Office is likely to scrutinize the adequacy of Origin's data minimization practices and access controls.
What Affected Customers Should Do
- Watch for phishing attempts — Expect targeted emails and SMS claiming to be from Origin or authorities
- Monitor bank accounts — Review statements for suspicious activity, particularly any attempts using partial card details as verification
- Be wary of unsolicited contact — Scammers will leverage this breach; Origin will not ask for passwords or full payment details over phone or email
- Register with the Origin support portal once individual notifications are sent
- Place fraud alerts with credit agencies if you receive confirmation your data was included