Origin Energy Limited, one of Australia’s leading energy providers, has confirmed a cybersecurity incident involving unauthorized access to customer data, raising concerns about data protection and critical infrastructure security.
The company disclosed on July 23, 2026, that threat actors gained unauthorized access to portions of its customer information systems, resulting in the exposure of sensitive personal data.
While the investigation is ongoing, Origin has acknowledged that the breach led to the disclosure of customer details including names, residential addresses, dates of birth, phone numbers, and account-related information.
Additionally, limited financial data may have been exposed, including the last four digits of credit cards and the final three digits of bank account numbers.
Origin clarified that this partial financial information cannot be used independently to conduct fraudulent transactions or access customer accounts. However, it still presents a potential risk when combined with other data sources.
Origin Confirms Security Breach
The breach was initially identified on July 22, when Origin began investigating suspicious activity within its systems. At that time, the company indicated that full financial details were not believed to be compromised.
However, subsequent findings confirmed that unauthorized data access and exfiltration had occurred. Origin CEO Frank Calabria issued a public apology, acknowledging the seriousness of the incident and its potential impact on customers.
He stated that protecting customer data remains a top priority and confirmed that affected individuals will be contacted directly as the company continues to assess the scope of the breach.
In response to the incident, Origin has initiated containment and remediation measures aimed at preventing further unauthorized access.
The company has engaged independent cybersecurity experts to assist with forensic investigation, threat analysis, and system hardening. These efforts are being conducted in parallel with ongoing collaboration with Australian government agencies.
Authorities involved in the response include the Australian Cyber Security Center (ACSC), the Australian Federal Police (AFP), and the Office of the Australian Information Commissioner (OAIC).
This multi-agency involvement suggests the incident is being treated with a high level of severity, potentially involving regulatory scrutiny and legal oversight.
To support affected customers, Origin has established dedicated communication channels and extended customer service availability, including weekend support hours.
Customers are being encouraged to remain vigilant for suspicious communications, including phishing attempts or identity fraud, which commonly follow data breaches involving personally identifiable information.
While the total number of impacted customers has not yet been disclosed, the incident highlights ongoing cybersecurity challenges facing the energy sector, which threat actors increasingly target due to its role in critical infrastructure.
Attacks on utility providers can have broader implications, including service disruption risks and downstream supply chain exposure. Origin has not publicly attributed the attack to any specific threat group, nor disclosed the initial attack vector.
However, the involvement of national cybersecurity authorities indicates that the investigation may extend into attribution and potential threat actor tracking.
As the investigation continues, further updates are expected regarding the scale of the breach, affected systems, and any additional mitigation steps.
The incident serves as a reminder of the importance of robust cybersecurity controls, continuous monitoring, and rapid incident response capabilities in protecting sensitive customer data within critical sectors.