VYPR
breachPublished Jul 23, 2026· Updated Jul 28, 2026· 6 sources

Origin Energy Confirms Customer Data Breach Affecting Millions

Australian energy giant Origin Energy has confirmed a significant data breach, with customer data compromised and an investigation underway to determine the full scope of the incident.

Origin Energy, a major Australian energy supplier serving approximately 5 million customers, announced on Thursday that it has suffered a data breach. The company is actively collaborating with federal agencies to investigate the incident.

Initially, on Wednesday, Origin Energy had stated it was "investigating a potential security incident" following a report by The Australian newspaper. The report indicated that an individual claiming to be a hacker had provided a sample of what they alleged were stolen company records. This prompted a more thorough investigation into the company's systems.

In a subsequent update, Origin Energy confirmed that customer data had indeed been compromised. The company is now focused on understanding the total number of affected customers. The compromised data may include sensitive personal information such as account details, the last four digits of credit card numbers, the last three digits of bank account numbers, as well as names, addresses, and dates of birth.

Origin Energy CEO Frank Calabria issued an apology to the affected customers, emphasizing the company's commitment to security. "One of our key priorities is taking action to secure our systems and ensure no further unauthorised access," Calabria stated. He added that the company is engaging independent cyber experts to assist in the investigation, working in parallel with authorities.

This breach at Australia's largest electricity and gas retailer occurs shortly after another significant incident involving compromised sensitive medical data from a network of Australian healthcare clinics. Partnered Health confirmed that patients from at least 21 clinics may have had their medical records stolen in a cyberattack, highlighting a concerning trend of data compromises within Australia.

The exact attack vector and the nature of the compromised data are still under investigation. Origin Energy has stated that its immediate priority is to secure its systems and prevent any further unauthorized access. The company is working closely with cybersecurity experts and law enforcement to manage the fallout from the incident.

This incident underscores the persistent threat of cyberattacks targeting large organizations and the critical importance of robust data protection measures. The compromise of personal and financial information can lead to identity theft, financial fraud, and significant distress for affected individuals. The ongoing investigation will likely shed more light on the methods used by the attackers and the specific vulnerabilities exploited.

As the investigation progresses, Origin Energy is expected to provide further updates to its customers and the public regarding the breach's scope, impact, and the steps being taken to mitigate the damage and enhance future security. The company's response, including its cooperation with authorities and cybersecurity experts, will be crucial in rebuilding trust with its customer base.

The threat actor, claiming to be "John Doe," alleges to possess data from 2 million Origin customers and has threatened to leak it within two weeks unless the company negotiates. This individual claims to have attempted contact with Origin's security, customer support, and board members without success. The exposed data types include full name, physical address, date of birth, phone number, account information, and the last four digits of credit cards and last three digits of bank accounts, though financial details are noted as incomplete.

The hacker claiming responsibility for the breach has stated they obtained the data of 2 million individuals and is threatening to leak it unless a ransom is paid. Origin Energy, which serves approximately 4.8 million customers, has confirmed unauthorized access to "some customers' data" and is working to determine the exact number of affected individuals and the specific types of information compromised, which may include names, addresses, dates of birth, phone numbers, account details, and partial payment card or bank account numbers.

The newly disclosed incident confirms that threat actors gained unauthorized access to customer data, including names, residential addresses, dates of birth, phone numbers, and account information. While the full scope is still under investigation, Origin has acknowledged that partial financial data, such as the last four digits of credit cards and bank account numbers, may have also been exposed, though they assert this data is insufficient for fraudulent transactions on its own.

The hacker who claimed responsibility for the Origin Energy breach later stated that an agreement had been reached with the company and no data would be leaked. However, Origin Energy has not confirmed this agreement, with its CEO noting that the matter is under ongoing investigation by authorities. Despite the potential for data not being publicly released, Origin acknowledged that threat actors could still exploit the compromised information for scams.

The breach at Origin Energy has been confirmed to affect approximately 900,000 customers, with names, addresses, dates of birth, and phone numbers exposed. For a subset of these customers, partial payment card or bank account details were also accessed, increasing the risk of phishing and social engineering attacks. Origin is actively investigating with cybersecurity specialists and has notified relevant Australian government agencies, including the Australian Cyber Security Centre and the Australian Federal Police.

Synthesized by Vypr AI
Origin Energy Confirms Customer Data Breach Affecting Millions · VYPR