Recent Breaches
Breaches
2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) stolen6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption stolenAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) stolen2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) stolenCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data stolenOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted stolenProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin stolenCheck-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026PowerSchool62.4M stolen62.4M records stolen2026DISA Global Solutions3.3M stolen3.3M records stolen2026Globe Life850K stolen850K records stolen
View All →
Breaking NewsUpdated as information becomes available
Back to Knowledge Vault
Breach AnalysisBreaking23 July 20265 min read

Origin Energy Confirms Customer Data Breach: 4.8 Million Retail Customers on Notice

Origin Energy, Australia's largest energy retailer, has confirmed unauthorised access and disclosure of customer data. Names, addresses, dates of birth, phone numbers, account information and partial card and bank details may be exposed.

Mark Fermor

Mark Fermor

Director & Co-Founder, Firevault

Share
Electricity pylons at night with a glowing magenta padlock symbol over an Australian city skyline, illustrating the Origin Energy customer data breach

On 23 July 2026, Origin Energy confirmed via an ASX statement that a third party had gained unauthorised access to some of its systems and that customer data had been disclosed. The confirmation came a day after the company first told the market it was investigating a "potential" security incident, and only after a hacker sent a sample of 50 customer records to The Australian.

What Origin has confirmed

Origin said affected customer data may include:

  • Name and address
  • Date of birth
  • Contact phone number
  • Account information
  • The last four digits of a credit card, or the last three digits of a bank account

The company had initially emailed customers to say it did "not believe the impacted information includes customer credit card or bank details". That position changed once the scope became clearer.

"I'm sorry this has happened. Customers trust Origin with their information, and I apologise for the impact this may cause," chief executive Frank Calabria said in a statement. "One of our key priorities is taking action to secure our systems and ensure no further unauthorised access."

How the incident surfaced

The breach was not first detected by Origin. It was first reported at 12:21pm on 22 July by The Australian, which had been contacted by an alleged attacker who supplied a sample of 50 customer records containing names, addresses, emails, dates of birth, phone numbers and bill history. Origin only alerted authorities after that sample was passed to it, and notified the ASX at 12:42pm the same day.

The ABC has also spoken to a person claiming responsibility, who provided what they described as a sample from a larger customer list and internal screenshots of Origin's systems. Analysis of the sample shows contact information that had not been publicly released in earlier Australian breaches.

Why this one matters

Origin is the country's largest energy retailer with more than 4.8 million customers across electricity, gas, LPG and internet. If the disclosed sample is representative of a broader dataset, this would be the largest known incident experienced by an Australian energy retailer, and it lands in a market still bruised by Optus and Medibank in 2022, Qantas in 2025 and, only last week, the Partnered Health GP network.

"Everybody has been on notice," UNSW cybersecurity professor Richard Buckland told the ABC. "That this is still happening is just concerning. How seriously does the Origin board take security? Because they are a power provider, you'd hope they take it seriously."

What Origin customers should do

  • Treat any unexpected call, text or email claiming to be from Origin as suspicious, especially anything asking to confirm identity, banking or account credentials.
  • Do not click links in messages that reference the breach. Go to originenergy.com.au directly.
  • Monitor bank statements for unusual activity, particularly small "test" transactions.
  • Consider a credit ban or credit monitoring given the combination of name, date of birth and address in the exposed dataset.

The pattern is not new

Every large Australian breach in the last four years has followed the same shape. A perimeter is compromised, a support or billing system is reached, and personal information sitting on an always-connected estate is copied out before defenders can respond. Optus, Medibank, Latitude, Qantas, Partnered Health and now Origin were all breached through the same structural weakness: valuable personal data lived on systems that were reachable from the internet, directly or through an integrated third party.

Firewalls, monitoring and encryption are necessary, but they operate on connected data. Once an attacker has valid credentials or a foothold, those controls become audit trail rather than prevention.

Where offline secure storage changes the picture

Not every dataset needs to be online. Historical billing records, archived identity documents, KYC scans, contracts, legal correspondence and long-tail customer records are often kept live for convenience, not necessity. When those datasets sit on an always-connected retail platform, they become part of the blast radius of any breach.

Offline Secure Storage keeps the copies that matter physically disconnected from the retail environment. An attacker who reaches the billing platform cannot reach data that has no network path. That is not a replacement for identity protection or endpoint controls, but it removes the single largest lever an attacker has: exfiltrating years of customer records in a single session.

For energy retailers, telcos, insurers and healthcare providers, the Origin incident is another reminder that the question is not whether the perimeter can be breached. It is which data an attacker can reach once inside.

Sources

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

Share this article

Breaking News
Breach Analysis23 July 20265 min read

Origin Energy Confirms Customer Data Breach: 4.8 Million Retail Customers on Notice

Origin Energy, Australia's largest energy retailer, has confirmed unauthorised access and disclosure of customer data. Names, addresses, dates of birth, phone numbers, account information and partial card and bank details may be exposed.

Origin Energy Confirms Customer Data Breach: 4.8 Million Retail Customers on Notice
Mark Fermor
Published by Mark Fermor, Director & Co-Founder