Origin Energy Investigates Potential Breach of Customer Data
July 22, 2026 – 8:53 am
Australia’s largest energy retailer has informed the ASX that some customer information may have been accessed without authorization, although it states card and bank details remain untouched.
Origin Energy, Australia’s dominant electricity and gas supplier, disclosed on July 22 to the Australian Securities Exchange (ASX) an ongoing investigation into potential unauthorized access to its customers’ data. The company expressed confidence that credit card or banking information was not compromised, but refrained from specifying the extent of the incident.
This revelation comes in a year marked by numerous high-profile corporate security breaches, ranging from a supply-chain compromise at Klue, which exposed LastPass customer records, to a second extortion group that emerged weeks later with its own demands.
Origin’s statement, currently lacking detailed specifics, is a result of either caution during the early stages of an investigation or the ongoing nature of its inquiries. The company revealed in its filing that investigations are "occurring as a matter of urgency" and that it will provide further updates “as appropriate.” Origin also notified the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner, the regulator overseeing Australia’s notifiable data breaches scheme.
Under this scheme, organizations are generally required to alert affected individuals and the regulator once a breach is deemed likely to cause significant harm, a threshold Origin has not yet indicated it has met.
The details surrounding the incident remain murky: how access was gained, its timeline, or whether any data actually left Origin’s systems. The company hasn’t identified an affected system, third-party vendor, or entry point. No threat actor has publicly claimed responsibility at the time of this writing.
However, according to Insurance Business, a person claiming to have breached Origin reached out to The Australian newspaper and asserted possession of records for millions of customers, providing samples containing names, addresses, dates of birth, phone numbers, and billing history. Although these claims have not been independently verified, Origin has neither confirmed nor denied their validity.
If accurate, the purported scope of the breach would be less severe due to the absence of financial credentials—the fastest route from a data breach to fraud. The company’s initial assessment indicates card and bank details were not exposed. While names, addresses, and dates of birth are less immediately damaging, they remain valuable for identity theft and subsequent waves of phishing that often follow public disclosures.
Australia has recently grappled with these lessons firsthand, as breaches at Optus and Medibank in 2022 compromised the personal data of millions, spurring regulatory changes and stiffer penalties for serious or repeated data breaches.
Global regulators have also watched as extortion crews become increasingly audacious, highlighting the ongoing challenge of securing sensitive information in an ever-evolving digital landscape.