Data breach at Origin Energy: 4.8M customers exposed

Origin Energy, Australia's leading energy provider, has confirmed a data breach involving unauthorized access to customers' personal information. The company is working with authorities to assess the extent of the compromise.
The Australian energy provider Origin Energy has confirmed a data breach affecting its customers. The incident, revealed on 22 July 2026, involves unauthorized access to personally identifiable information. The company, which has 4.8 million customers, is investigating to determine the exact number of individuals affected.
Potentially accessed data without authorization includes full names, physical addresses, dates of birth, and phone numbers. Account information, the last four digits of credit cards, and the last three digits of bank accounts are also among the affected elements. Origin states that these partial financial details do not enable unauthorized transactions.
Sensitive data accessed without authorization
Origin Energy, Australia’s leading energy retailer, supplies electricity, natural gas, and broadband internet services. Listed on the Australian Stock Exchange, the company reports an annual revenue of 8.5 billion dollars. It also holds a 20% stake in Octopus, a UK-based renewable energy provider.
An individual (John Doe) claims responsibility for the breach and threatens to publish the data of 2 million customers within two weeks if Origin Energy does not contact him via the Signal app. The company has not responded to his attempts to communicate, which were directed at security teams, customer service, and executives.
Immediate measures and collaboration with authorities
Frank Calabria, CEO of Origin Energy, has apologized to customers. He assures that measures are being taken to block any further unauthorized access. Affected customers are receiving individual notifications and have access to a dedicated portal for assistance.
The company has reported the incident to the Australian Federal Police, the Australian Cyber Security Centre, and the Office of the Australian Information Commissioner. These agencies are assisting Origin in its investigation. Independent cybersecurity experts have been engaged to strengthen system protections.
A context marked by repeated cyberattacks
This breach follows several similar incidents in Australia. The Partnered Health clinic network recently confirmed the theft of patient medical records. Twenty-one facilities are reportedly affected.
Origin Energy emphasizes that data security remains an absolute priority. The company continues its investigations to assess the full extent of the compromise and mitigate its consequences.
Key Points
- Data breach confirmed by Origin Energy, involving unauthorized access to data of up to 4.8 million customers
- Affected data includes names, addresses, dates of birth, phone numbers, and partial financial information
- An individual (John Doe) claims responsibility for the breach and threatens to publish data of 2 million customers
- Origin Energy is collaborating with Australian authorities and cybersecurity experts to investigate
- Context of repeated cyberattacks in Australia, particularly in the healthcare sector
Sources
- BleepingComputer - "Australian energy provider Origin says data breach exposes client data". (secondary)
- The Record (Recorded Future) - "Major Australian energy supplier confirms customer data compromised". (secondary)
Transparency: 2 sources (0 primary, 2 secondary). Verification: 23 July 2026.
Truthyx - 23 July 2026