Origin Energy, an Australian energy provider, has confirmed that unauthorized access to customer information has affected approximately 900,000 current and former customers.
The company has completed its initial review of the data security incident, and a broader forensic investigation is still ongoing. Frank Calabria, the CEO of Origin, apologized to customers and emphasized that the company is prioritizing support for those whose information was accessed.
Origin has started reaching out to the affected individuals. It has expanded its customer support hours and established a dedicated incident response contact line.
The company first disclosed a potential security incident on July 22, 2026. Origin had been reviewing a possible threat since early July but initially did not consider the information credible.
However, new information emerged on July 22, leading the company to treat the matter as a possible compromise and to begin notifying customers as a precaution.
Origin Confirms Data Breach
On July 23, Origin confirmed that an unauthorized party had accessed and disclosed some customer data. The affected information may include customer names, residential addresses, dates of birth, phone numbers, and Origin account information.
For some customers, the exposed data may also contain the last four digits of a credit card or the last three digits of a bank account. Origin has stated that incomplete payment card and bank account details cannot independently be used to access accounts or make purchases.
However, the combination of personal identity and account data could increase the risk of targeted phishing, impersonation, and social engineering scams.
The company is working with independent cybersecurity and forensic specialists to contain the incident, determine its scope, and secure the affected systems.
They have also engaged with Australian government agencies, including the Australian Cyber Security Center, the National Office of Cyber Security, and the Australian Federal Police.
Additionally, Origin notified the Office of the Australian Information Commissioner, Australia’s privacy regulator. Authorities are investigating the incident as a criminal matter, which limits the technical and operational details Origin can publicly disclose at this time.
Affected customers have been offered specialist identity and cyber support services. Origin has warned all customers to stay vigilant for unexpected calls, emails, or text messages claiming to be related to their Origin account.
Customers should avoid clicking links in unsolicited messages and verify callers independently through official Origin contact channels. The company also advises customers never to share passwords, financial information, or personal details unless they have confirmed the identity of the requester.
Furthermore, Origin recommends enabling two-step authentication on personal email and online accounts whenever possible. Email accounts are especially crucial, as attackers can use them to reset passwords for other services.
Customers seeking assistance can contact Origin via its dedicated incident line or email. The company has stated that it will provide further updates as its investigation continues.