Origin Energy Data Breach Exposes 900,000 Customer Records

Origin Energy, a leading Australian energy provider, has confirmed a significant data breach affecting approximately 900,000 current and former customers. The company disclosed that unauthorized access to its systems resulted in the exposure of sensitive personal information.

The compromised data includes customer names, residential addresses, dates of birth, phone numbers, and account details. Additionally, partial financial information, such as the last four digits of credit card numbers and the final three digits of bank account numbers, was accessed. While this partial data cannot be used independently for fraudulent transactions, it raises concerns about potential risks when combined with other information.

The breach was initially identified on July 22, 2026, when Origin began investigating suspicious activity within its systems. Subsequent findings confirmed that unauthorized data access and exfiltration had occurred. CEO Frank Calabria issued a public apology, emphasizing the company’s commitment to protecting customer data and confirming that affected individuals will be contacted directly as the investigation continues.

In response to the incident, Origin has implemented containment and remediation measures to prevent further unauthorized access. The company has engaged independent cybersecurity experts to assist with forensic investigation, threat analysis, and system hardening. These efforts are being conducted in collaboration with Australian government agencies, including the Australian Cyber Security Centre (ACSC), the Australian Federal Police (AFP), and the Office of the Australian Information Commissioner (OAIC).

To support affected customers, Origin has established dedicated communication channels and extended customer service availability, including weekend support hours. Customers are encouraged to remain vigilant for suspicious communications, such as phishing attempts or identity fraud, which commonly follow data breaches involving personally identifiable information.

While the total number of impacted customers has not yet been disclosed, the incident highlights ongoing cybersecurity challenges facing the energy sector, which threat actors increasingly target due to its role in critical infrastructure.

This breach underscores the critical importance of robust cybersecurity measures within the energy sector. As providers of essential services, energy companies must prioritize the protection of customer data to maintain trust and ensure the security of critical infrastructure. Customers should remain vigilant and adopt best practices for personal data protection, including monitoring accounts for unusual activity and being cautious of unsolicited communications.