Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2094+ Articles
154+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Origin Energy Data Breach Affects 900,000 Australians
Origin Energy Data Breach Affects 900,000 Australians
NEWS

Origin Energy Data Breach Affects 900,000 Australians

Australian energy giant Origin Energy confirmed a data breach exposing the personal and partial financial information of approximately 900,000 current and former customers, after a hacker exploited a third-party customer management platform and used credentials from a terminated employee.

Dylan H.

News Desk

July 28, 2026
4 min read

Origin Energy, one of Australia's largest energy retailers serving approximately 4.8 million customers, confirmed a significant data breach on July 22, 2026, after detecting anomalous activity on its customer management platform. The incident exposed the personal and partial financial information of roughly 900,000 current and former customers, with the attacker claiming access to data for as many as two million individuals.

What Happened

An attacker operating under the alias "John Doe" claimed responsibility for the breach and provided details consistent with a targeted intrusion. According to the hacker's own account — corroborated in part by Origin's investigation — they exploited a customer management platform supplied by third-party technology provider Kraken Technologies, describing the platform as "poorly protected."

Critically, the attacker gained initial access using credentials belonging to a terminated former Origin employee — a textbook case of inadequate offboarding and privileged access revocation. Once inside, the attacker maintained undetected access for approximately three weeks before exfiltrating customer data, a dwell time that highlights significant gaps in Origin's security monitoring posture.

Data Exposed

Origin confirmed the following categories of data were compromised for affected customers:

  • Full name and home address
  • Date of birth
  • Phone number
  • Account information (plan details, usage history)
  • Partial payment card and bank account details (last four digits of credit card and bank account numbers only)

While no complete financial credentials, passwords, or government ID numbers were confirmed as stolen, the combination of this personally identifiable information is sufficient to enable convincing phishing campaigns, identity fraud, SIM-swapping attacks, and social engineering of financial institutions.

Hacker Contact and Unusual Resolution

The breach disclosure followed an unusual pattern. The attacker reportedly sent warnings to Origin's security team, customer support channels, and board executives before going public — claims that went unanswered according to the hacker's account. A countdown website was subsequently erected threatening to publish the full dataset unless Origin made contact via Signal to negotiate.

As of July 25, 2026, a person claiming to be the attacker told media they had reached a private agreement with Origin and would refrain from selling or publishing the stolen data. Origin has not publicly confirmed any such arrangement. Security researchers have described this incident as atypical given its semi-public nature and the attacker's direct communication strategy.

Origin's Response

Origin Energy took the following steps following discovery:

  • Engaged the Australian Cyber Security Centre (ACSC) and the Australian Federal Police
  • Notified the Office of the Australian Information Commissioner (OAIC)
  • Extended customer support hours and established a dedicated breach hotline
  • CEO Frank Calabria issued a public apology

Moody's flagged potential long-term financial costs associated with the breach, and Origin's share price declined following public disclosure.

What Affected Customers Should Do

If you are or were an Origin Energy customer, take the following steps:

  1. Watch for phishing attempts — unsolicited emails, SMS, or calls claiming to be from Origin
  2. Be suspicious of callers who already know your partial account details — attackers may use the stolen data to impersonate Origin staff
  3. Enable multi-factor authentication on your Origin account and linked email address
  4. Monitor bank accounts and credit cards for unauthorized activity, even if only partial card numbers were taken
  5. Consider placing a credit alert with Australian credit bureaus (Equifax, Illion, Experian Australia)

Broader Context

This incident follows a pattern of attackers exploiting third-party customer management platforms and stale privileged credentials to breach large organizations. The three-week dwell time before detection is a particular concern — organizations relying on Thrift services or large-scale customer management platforms should review their third-party access scopes, offboarding processes, and user behavior analytics capabilities.

The Energy sector has become an increasingly attractive target given the volume of consumer PII held by large retailers and the relatively mature but often legacy nature of operational technology environments.

References

  • Security Week — Origin Energy Data Breach Affects 900,000 Australians
  • BleepingComputer — Australian Energy Provider Origin Says Data Breach Exposes Client Data
  • Information Age — Hacker Claims Deal Struck with Origin Over Data Breach
#Data Breach#Australia#Energy Sector#Supply Chain#Insider Threat#Third Party Risk

Related Articles

Origin Energy Data Breach: Fired Employee's Credentials Expose Up to 2 Million Australian Customers

Australian energy giant Origin Energy has confirmed a data breach affecting up to 2 million customers after a threat actor exploited credentials belonging to a terminated employee that were never revoked on the Kraken customer management platform.

5 min read

Major Australian Energy Supplier Confirms Customer Data Compromised

Origin Energy confirmed that customer data was exposed in a recent breach, as the company works to assess how many Australians are affected.

3 min read

Origin Energy Data Breach Exposes Millions of Australian Customers

Australia's largest energy retailer has confirmed a data breach affecting up to 2 million customers, with exposed data including full names, contact...

4 min read
Back to all News