Skip to content
Data breachOngoing

Australian energy giant Origin Energy discloses customer data breach (2026)

Origin Energy told the ASX it was investigating a cyberattack, then confirmed unauthorised access to some customers' data in a breach later put at around 900,000 people.

Victim
Origin Energy
users
900.0K

On 22 July 2026, Origin Energy โ€” one of Australia's largest electricity and gas retailers โ€” disclosed to the Australian Securities Exchange (ASX) that it was investigating a potential security incident that might involve unauthorised access to some customers' data. The next afternoon, in a further filing, the company confirmed that unauthorised access to and disclosure of customer data had in fact occurred.

What was exposed

Origin said the affected information included customers' names, addresses, dates of birth, phone numbers, and account details, along with limited payment information such as the last four digits of a card or the BSB and last three digits of a bank account. The company stressed that full credit-card and bank-account details did not appear to be among the exposed data. In a public statement issued the following week, Origin put the number of current and former customers affected at approximately 900,000, a figure that grew as the company worked through its records.

Response and investigation

Origin activated its incident-response plans, engaged external cybersecurity specialists, and began notifying affected customers. The breach was referred to and examined by Australian authorities, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police, and the Office of the Australian Information Commissioner, which oversees privacy obligations under Australian law.

Why it matters

As an energy retailer serving millions of households, Origin sits within Australia's critical-infrastructure perimeter, and a breach of its customer base feeds directly into the identity-fraud economy that has followed successive large Australian data breaches. The incident also illustrates the disclosure discipline expected of ASX-listed companies: Origin moved from an initial "investigating" notice to a confirmation of unauthorised access within roughly a day, keeping the market informed as its understanding of the event evolved.

Timeline

  1. Origin Energy files a notice with the Australian Securities Exchange saying it is investigating a potential security incident that may involve unauthorised access to some customer data.

  2. In a follow-up ASX statement, Origin confirms there was unauthorised access to and disclosure of some customers' data.

  3. Origin publicly confirms the breach affected roughly 900,000 current and former customers.

Sources

  1. abc.net.auhttps://www.abc.net.au/news/2026-07-23/origin-energy-confirms-unauthorised-access-customer-data/106948052
  2. securityweek.comhttps://www.securityweek.com/data-breach-confirmed-after-australian-energy-giant-origin-is-hacked/
  3. cyberdaily.auhttps://www.cyberdaily.au/security/13952-hacked-origin-energy-confirms-customer-data-impacted-following-data-breach
  4. cyberdaily.auhttps://www.cyberdaily.au/security/13942-breached-origin-energy-discloses-data-breach-to-asx

Related incidents