
Key Points
- 01Origin Energy says about 900,000 customers’ data was accessed
- 02Compromised data may include personal details and partial payment IDs
- 03New information on 22 July triggered formal incident notifications
- 04A criminal investigation is under way with multiple Australian agencies
Origin discloses scale of customer data access
Origin Energy has disclosed that information relating to approximately 900,000 current and former customers was accessed in a recent data security incident. The figure is based on the company’s initial review, which it says has now completed its first phase. The incident involves both existing and past account holders, indicating a broad footprint across its customer base.
The company says its assessment remains ongoing, but the current estimate provides the first formal indication of the scope of the exposure. Origin has not detailed how long attackers may have had access, focusing instead on clarifying what types of information may have been viewed and how affected customers are being supported.
Types of information potentially exposed
Origin says the accessed information may include customer names, residential addresses, dates of birth and contact phone numbers. In addition, account information tied to energy services may have been viewed. These data points collectively can help identify individuals and link them to specific accounts.
The company also reports that limited payment identifiers may have been accessed, specifically the last four digits of credit cards and the last three digits of bank accounts. Full payment details have not been listed among the accessed fields, and Origin characterises the payment-related exposure as partial identifiers rather than complete card or account numbers.
Timeline from initial threat to incident notification
Origin explains that it had been reviewing a potential security threat since early July. At that time, the threat was not assessed as credible, and no incident was confirmed. The situation changed on 22 July, when new information indicated a potential security incident involving customer data.
Following this development, Origin says it notified the market and its customers as a precaution. This step marked the shift from internal threat monitoring to a formal incident response, including public communication and engagement with external specialists and authorities.
Investigation, government involvement and customer support
The matter is now the subject of an active criminal investigation. Origin says it is working with cybersecurity and forensic specialists to understand the incident and its impact in more detail. The company is also coordinating with several Australian government bodies, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police and the Office of the Australian Information Commissioner.
In parallel with the investigation, Origin is rolling out measures to support impacted customers. It is contacting those whose information was accessed, extending customer support hours and providing a dedicated contact number for incident-related queries. Specialist identity and cyber support services have been made available, aimed at assisting affected individuals in managing potential consequences of the data access.
Key Takeaways
- 01Origin’s initial review points to a large-scale exposure, with about 900,000 customer records affected, underscoring the breadth of the incident.
- 02The data involved combines personal identifiers, account details and partial payment information, increasing potential sensitivity even without full card numbers.
- 03A gap between the early-July threat review and the 22 July incident confirmation highlights how evolving information can change risk assessments.
- 04The involvement of multiple national cyber and law-enforcement agencies signals that the event is being treated as a serious criminal matter.
- 05Origin’s customer outreach and specialist support offerings indicate a focus on mitigation and assistance as the technical and legal investigations continue.
References
- https://www.yahoo.com/news/world/articles/origin-says-data-breach-affected-015000561.html
- https://www.abc.net.au/news/2026-07-28/origin-energy-data-breach-900k-customers-impacted/106961804
- https://www.brisbanetimes.com.au/business/companies/origin-energy-says-900-000-customers-had-their-data-hacked-20260728-p60j6y.html
- https://www.techrepublic.com/article/news-origin-energy-customer-data-breach/