Origin Energy has confirmed that customer records were accessed in a data breach at Australia’s largest energy retailer, and that about 900,000 customer accounts are affected. The records include names, addresses, dates of birth and partial financial details, according to ABC News.
The company told the Australian Securities Exchange about the incident on Thursday 23 July, and confirmed the number of affected customers five days later, on 28 July. The 23 July statement confirmed that data had been accessed; the later statement put a figure on how many customers were caught up in it.
What Origin Told the ASX
Origin supplies electricity and gas to households and businesses across Australia. As a listed company, it must tell the market about information that could affect its share price. The requirement is designed to keep the market informed as events develop. That is why the incident moved from an internal response to a public statement within a single afternoon.
Origin’s notice said there had been “unauthorised access and disclosure” of customer data. The wording reversed the position the company had taken on Wednesday, and it turned the breach into a confirmed event rather than a claim circulating in public.
The phrase covers two things. Unauthorised access describes an intrusion into a company’s systems, while disclosure describes data being made available outside them. Origin’s notice used both.
How the Breach Surfaced
The breach entered public view when a sample of 50 customer records was sent to a newspaper. According to ABC News, Origin’s notice to the ASX was lodged 21 minutes later. The sample gave the first public view of what had been taken.
It was a fraction of the total that would later be confirmed, and the scale of the breach was not established until the company’s own count, five days on, put the figure at about 900,000 accounts.
What Was Taken
The data accessed includes customer names, addresses and dates of birth, along with partial financial details. According to ABC News, those details run to the last four digits of card numbers and the last three digits of bank account numbers.
Partial digits of that kind cannot be used to access an account on their own. Combined with a name, address and date of birth, though, they can make a fraudulent approach sound genuine, which is why the advice to customers centres on phishing and social engineering.
900,000 Accounts Against a Claim of Two Million
Origin confirmed the number of customers affected on 28 July. The figure of about 900,000 accounts is well below the claim of two million records that circulated when the sample first appeared, and only the company’s figure has been confirmed.
The two million figure came with the sample records, and the company has not confirmed anything close to it. Origin has told the 900,000 affected customers that the number is far smaller than the earlier claim suggested.
For customers, the size of the final figure does not change much. Whatever the total, the types of data taken are the same, and the risk they carry is a fraudulent approach rather than money moving out of an account.
What Customers Should Do Now
The main risk to affected customers is phishing and social engineering. Stolen details are used to make calls, texts and emails appear to come from a trusted organisation, and a caller who can quote a customer’s name, address and date of birth sounds credible in a way that a cold caller does not.
Origin has opened a dedicated contact line for the incident, and customers do not need to wait for the company to contact them before getting in touch. Customers with questions about their data can use it to confirm what has happened without relying on the numbers or links supplied in an unexpected message. Anyone who receives a suspicious call, text or email about the breach should check through that line, or through the company’s own website, rather than through the contact details in the message.
A message that arrives without warning and asks for personal details, a payment or a password should be treated as suspect, even when it looks official. Passwords and one-time codes should never be given out in response to an unexpected call, and account activity and statements should be watched for anything unfamiliar.
The response also involves the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner. The Australian Cyber Security Centre leads national coordination on cyber security, the Australian Federal Police carries the criminal investigation, and the Office of the Australian Information Commissioner oversees the privacy side of the response.
The company’s confirmed figure remains 900,000 accounts.
Related: Global Web Disruptions as Cloudflare Outage Exposes Fragility of Internet Infrastructure
Sources: ABC News, https://www.abc.net.au/news/2026-07-23/origin-energy-confirms-unauthorised-access-customer-data/106948052; MarketIndex, https://www.marketindex.com.au/asx/org/announcements/update-on-data-security-incident-2A1685659; Cyber Daily, https://www.cyberdaily.au/security/13952-hacked-origin-energy-confirms-customer-data-impacted-following-data-breach
Photo: BalticServers.com, CC BY-SA 3.0, via Wikimedia Commons.
Illustrative – a data centre server aisle. This photograph is not of Origin Energy's systems.


