← Blog

Origin Energy Confirms Customer Data Breach

Share on X

On July 23, 2026, Australia’s largest electricity and gas retailer Origin Energy confirmed what it had only called a “potential” incident the day before: there has been unauthorized access and disclosure of some customers’ data.

That confirmation, posted on Origin’s customer update page and covered by Reuters, also walked back an earlier reassurance. On July 22 Origin said it did not believe credit-card or bank details were involved. The July 23 update says affected customers may have had the last four digits of a credit card or the last three digits of a bank account exposed—still truncated, but no longer “none.”

What Origin says was exposed

For affected customers, impacted data may include name, address, date of birth, contact phone number, account information, and those truncated payment identifiers. Origin states incomplete card or bank digits cannot be used to make purchases or access accounts.

Origin is still assessing how many customers are in scope and says it will contact people it can confirm were affected. CEO Frank Calabria apologized publicly and said Origin is working with independent cyber experts alongside the ACSC, AFP, and OAIC.

What remains unclear

Media coverage of an actor sample and claims of roughly two million customers circulated before confirmation. Origin has not verified that headline number. Until Origin publishes an attested count, treat large online figures as unverified.

Action items

  1. Watch for Origin’s official email or mail notice; activate any monitoring only with codes from that notice.
  2. Ignore cold calls or SMS about “Origin refunds” or “re-verify your meter”—use contacts on originenergy.com.au.
  3. Monitor bank and card statements even though only truncated digits are described.
  4. Report phishing to Origin’s published channels and Australia’s cyber reporting services.

Canonical record

Origin Energy July 2026 breach. Sources: Origin update, Reuters.

July 24 update: Press reported an actor claiming a private settlement and alleging access via a fired former employee’s credentials; Origin declined to comment on those claims. Treat that pathway as unverified unless Origin confirms. Coverage: DataBreaches.net.