Origin Energy has confirmed that an unauthorized party accessed and disclosed customer data, one day after the Australian energy provider initially described the matter as a potential security incident.
The company has not disclosed how many customers were affected or explained how the attacker gained access to its systems. Origin said it is still determining the scope of the breach and will contact customers whose information it confirms was involved.
Origin disclosed the breach in a July 23 customer data security incident update, stating that its investigation had confirmed both unauthorized access and the disclosure of customer information.
Personal and account information exposed
Origin said the compromised data may include customer names, addresses, dates of birth, phone numbers, and account information.
Some affected records may also contain the last 4 digits of a credit card number or the last 3 digits of a bank account number. The company said the incomplete financial details cannot be used by themselves to make purchases or access customer accounts.
Origin has not reported the exposure of complete credit card numbers, full bank account numbers, passwords, or account login credentials.
Although partial payment details present less immediate financial risk than complete card or banking information, the broader collection of personal data could still be used in targeted phishing, impersonation, and social engineering attacks.
A scammer possessing a customer’s name, address, phone number, date of birth, and legitimate account details could use that information to make a fraudulent call, email, or text message appear more convincing.
Incident confirmed after initial investigation
Origin first publicly acknowledged the incident on July 22, when it said it was urgently investigating potential unauthorized access to some customer data.
At that stage, the company said it did not believe the affected information included customer credit card or bank details. Its July 23 update clarified that truncated credit card and bank account numbers may have been included in the exposed records.
Origin has not disclosed when the intrusion began, when it was detected, how long the unauthorized access continued, or which systems were affected.
The company also has not identified a suspected threat actor, attributed the breach to ransomware, or confirmed receiving an extortion demand.
Origin secures systems and contacts authorities
Origin CEO Frank Calabria apologized to customers and said the company was working to prevent further unauthorized access.
“I’m sorry this has happened. Customers trust Origin with their information, and I apologise for the impact this may cause,” Calabria said.
Origin said it has engaged independent cybersecurity specialists to assist with its investigation and response. The company is also working with the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner.
The involvement of those agencies does not establish who carried out the attack or whether criminal charges are expected. Their work may include supporting the technical investigation, assessing risks to affected customers, and reviewing Origin’s obligations under Australian privacy and breach notification laws.
Origin said it has established a dedicated contact number and additional resources for customers seeking assistance. The company also extended its incident support hours across the weekend of July 25 and 26.
Customer count remains unknown
Origin is still working to establish the total number of impacted customers. The company said it would directly notify individuals when investigators confirm that their information was affected.
Customers should be cautious of unsolicited communications claiming to relate to the incident, particularly messages requesting passwords, payment details, verification codes, or immediate account action.
Anyone receiving a suspicious message should avoid following embedded links and instead access their Origin account through the company’s official website or application. Customers should also monitor financial statements and Origin account activity for unfamiliar transactions or changes.
Origin’s July 24 update did not provide additional technical findings or an affected customer count. The company said its support team would remain available during the weekend while the investigation continued.











