---
title: "Origin Energy Confirms Customer Data Breach: 4.… | Firevault"
description: "Origin Energy, Australia's largest energy retailer, has confirmed unauthorised access and disclosure of customer data. Names, addresses, dates of birth, phone…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/origin-energy-customer-data-breach-2026#webpage",
      "url": "https://fire-vault.com/news/origin-energy-customer-data-breach-2026",
      "name": "Origin Energy Confirms Customer Data Breach: 4.…",
      "description": "Origin Energy, Australia's largest energy retailer, has confirmed unauthorised access and disclosure of customer data. Names, addresses, dates of birth, phone…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/e012dd5c-2830-4c73-b8eb-7f367187be76/origin-energy-data-breach-2026-2x.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/origin-energy-customer-data-breach-2026#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/origin-energy-customer-data-breach-2026#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Origin Energy Confirms Customer Data Breach: 4.8 Million Retail Customers on Notice",
          "item": "https://fire-vault.com/news/origin-energy-customer-data-breach-2026"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Origin Energy Confirms Customer Data Breach: 4.8 Million Retail Customers on Notice",
      "description": "Origin Energy, Australia's largest energy retailer, has confirmed unauthorised access and disclosure of customer data. Names, addresses, dates of birth, phone numbers, account information and partial card and bank details may be exposed.",
      "url": "https://fire-vault.com/news/origin-energy-customer-data-breach-2026",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/e012dd5c-2830-4c73-b8eb-7f367187be76/origin-energy-data-breach-2026-2x.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/e012dd5c-2830-4c73-b8eb-7f367187be76/origin-energy-data-breach-2026-2x.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/e012dd5c-2830-4c73-b8eb-7f367187be76/origin-energy-data-breach-2026-2x.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/e012dd5c-2830-4c73-b8eb-7f367187be76/origin-energy-data-breach-2026-2x.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-07-23T06:00:00+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/origin-energy-customer-data-breach-2026"
      },
      "inLanguage": "en-GB",
      "articleSection": "Breach Analysis",
      "wordCount": 800,
      "keywords": "Origin, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "On 23 July 2026, Origin Energy confirmed via an ASX statement that a third party had gained unauthorised access to some of its systems and that customer data had been disclosed. The confirmation came a day after the company first told the market it was investigating a \"potential\" security incident, and only after a hacker sent a sample of 50 customer records to The Australian . What Origin has con",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What Origin has confirmedHow the incident surfacedWhy this one mattersWhat Origin customers should doThe pattern is not newWhere offline secure storage cha…SourcesMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Breach Analysis · 23 July 2026 

# Origin Energy Confirms Customer Data Breach: 4.8 Million Retail Customers on Notice

Origin Energy, Australia's largest energy retailer, has confirmed unauthorised access and disclosure of customer data. Names, addresses, dates of birth, phone numbers, account information and partial card and bank details may be exposed.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

5 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Forigin-energy-customer-data-breach-2026)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Forigin-energy-customer-data-breach-2026&text=Origin%20Energy%20Confirms%20Customer%20Data%20Breach%3A%204.8%20Million%20Retail%20Customers%20on%20Notice%0A%0AOrigin%20Energy%2C%20Australia's%20largest%20energy%20retailer%2C%20has%20confirmed%20unauthorised%20access%20and%20disclosure%20of%20customer%20data.%20Names%2C%20addresses%2C%20dates%20of%20birth%2C%20phone%20numbers%2C%20account%20information%20and%20partial%20card%20and%20bank%20details%20may%20be%20exposed.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Forigin-energy-customer-data-breach-2026)[](mailto:?subject=Origin%20Energy%20Confirms%20Customer%20Data%20Breach%3A%204.8%20Million%20Retail%20Customers%20on%20Notice&body=Origin%20Energy%2C%20Australia's%20largest%20energy%20retailer%2C%20has%20confirmed%20unauthorised%20access%20and%20disclosure%20of%20customer%20data.%20Names%2C%20addresses%2C%20dates%20of%20birth%2C%20phone%20numbers%2C%20account%20information%20and%20partial%20card%20and%20bank%20details%20may%20be%20exposed.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Forigin-energy-customer-data-breach-2026)

![Electricity pylons at night with a glowing magenta padlock symbol over an Australian city skyline, illustrating the Origin Energy customer data breach](/__l5e/assets-v1/e012dd5c-2830-4c73-b8eb-7f367187be76/origin-energy-data-breach-2026-2x.jpg)

Electricity pylons at night with a glowing magenta padlock symbol over an Australian city skyline, illustrating the Origin Energy customer data breach

Why it matters

## What this means for organisations holding critical data

Origin Energy, Australia's largest energy retailer, has confirmed unauthorised access and disclosure of customer data. Names, addresses, dates of birth, phone numbers, account information and partial card and bank details may be exposed.

In this analysis

1.  01 [What Origin has confirmed](#section-0)
2.  02 [How the incident surfaced](#section-1)
3.  03 [Why this one matters](#section-2)
4.  04 [What Origin customers should do](#section-3)
5.  05 [The pattern is not new](#section-4)
6.  06 [Where offline secure storage cha…](#section-5)

**On this page**[What Origin has confirmed](#section-0)[How the incident surfaced](#section-1)[Why this one matters](#section-2)[What Origin customers should do](#section-3)[The pattern is not new](#section-4)[Where offline secure storage cha…](#section-5)

On 23 July 2026, **Origin Energy** confirmed via an ASX statement that a third party had gained unauthorised access to some of its systems and that customer data had been disclosed. The confirmation came a day after the company first told the market it was investigating a "potential" security incident, and only after a hacker sent a sample of 50 customer records to _The Australian_.

## What Origin has confirmed

Origin said affected customer data may include:

-   Name and address
-   Date of birth
-   Contact phone number
-   Account information
-   The last four digits of a credit card, or the last three digits of a bank account

The company had initially emailed customers to say it did "not believe the impacted information includes customer credit card or bank details". That position changed once the scope became clearer.

"I'm sorry this has happened. Customers trust Origin with their information, and I apologise for the impact this may cause," chief executive Frank Calabria said in a statement. "One of our key priorities is taking action to secure our systems and ensure no further unauthorised access."

## How the incident surfaced

The breach was not first detected by Origin. It was first reported at 12:21pm on 22 July by _The Australian_, which had been contacted by an alleged attacker who supplied a sample of 50 customer records containing names, addresses, emails, dates of birth, phone numbers and bill history. Origin only alerted authorities after that sample was passed to it, and notified the ASX at 12:42pm the same day.

The ABC has also spoken to a person claiming responsibility, who provided what they described as a sample from a larger customer list and internal screenshots of Origin's systems. Analysis of the sample shows contact information that had not been publicly released in earlier Australian breaches.

## Why this one matters

Origin is the country's largest energy retailer with more than **4.8 million customers** across electricity, gas, LPG and internet. If the disclosed sample is representative of a broader dataset, this would be the largest known incident experienced by an Australian energy retailer, and it lands in a market still bruised by Optus and Medibank in 2022, Qantas in 2025 and, only last week, the Partnered Health GP network.

"Everybody has been on notice," UNSW cybersecurity professor Richard Buckland told the ABC. "That this is still happening is just concerning. How seriously does the Origin board take security? Because they are a power provider, you'd hope they take it seriously."

## What Origin customers should do

-   Treat any unexpected call, text or email claiming to be from Origin as suspicious, especially anything asking to confirm identity, banking or account credentials.
-   Do not click links in messages that reference the breach. Go to originenergy.com.au directly.
-   Monitor bank statements for unusual activity, particularly small "test" transactions.
-   Consider a credit ban or credit monitoring given the combination of name, date of birth and address in the exposed dataset.

## The pattern is not new

Every large Australian breach in the last four years has followed the same shape. A perimeter is compromised, a support or billing system is reached, and personal information sitting on an always-connected estate is copied out before defenders can respond. Optus, Medibank, Latitude, Qantas, Partnered Health and now Origin were all breached through the same structural weakness: valuable personal data lived on systems that were reachable from the internet, directly or through an integrated third party.

Firewalls, monitoring and encryption are necessary, but they operate on connected data. Once an attacker has valid credentials or a foothold, those controls become audit trail rather than prevention.

## Where offline secure storage changes the picture

Not every dataset needs to be online. Historical billing records, archived [identity documents](/oss-for-identity-documents), KYC scans, contracts, legal correspondence and long-tail customer records are often kept live for convenience, not necessity. When those datasets sit on an always-connected retail platform, they become part of the blast radius of any breach.

[Offline Secure Storage](/why-oss) keeps the copies that matter physically disconnected from the retail environment. An attacker who reaches the billing platform cannot reach data that has no network path. That is not a replacement for identity protection or endpoint controls, but it removes the single largest lever an attacker has: exfiltrating years of customer records in a single session.

For energy retailers, telcos, insurers and healthcare providers, the Origin incident is another reminder that the question is not whether the perimeter can be breached. It is which data an attacker can reach once inside.

## Sources

-   [ABC News, Origin Energy confirms unauthorised access and disclosure of customer data](https://www.abc.net.au/news/2026-07-23/origin-energy-confirms-unauthorised-access-customer-data/106948052)
-   [Sydney Morning Herald, Origin Energy confirms data breach has exposed customer information](https://www.smh.com.au/business/consumer-affairs/origin-energy-confirms-data-breach-has-exposed-customer-information-20260723-p60i0c.html)
-   [Australian Financial Review, Origin Energy confirms customer data leak in cyberattack](https://www.afr.com/companies/energy/origin-energy-confirms-customer-data-leak-in-cyberattack-20260723-p60huh)
-   [7NEWS, Origin Energy confirms unauthorised access to customers'' personal information](https://7news.com.au/news/origin-energy-confirms-unauthorised-access-to-customers-personal-information-c-22619530)
-   [ABC News, Origin Energy investigating potential customer data breach](https://www.abc.net.au/news/2026-07-22/origin-energy-investigating-potential-data-breach/106944660)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

Related Reading

## You may also find these useful

[

![AnMed Closes Facilities Following Ransomware Attack and Data Claims](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/anmed-facility-closures-following-ransomware-cyberattack-1786723492583.png)

Breach Analysis 

### AnMed Closes Facilities Following Ransomware Attack and Data Claims

South Carolina health system AnMed was forced to close 83 facilities following a cyberattack. Threat actors subsequently claimed to hold 6 terabytes of sensitive patient records.

14 Aug 2026 4 min 







](/news/anmed-facility-closures-following-ransomware-cyberattack)[

![US directive allows private firms to conduct offensive cyber operations](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/us-directive-private-firms-offensive-cyber-operations-1786723418300.png)

Breach Analysis 

### US directive allows private firms to conduct offensive cyber operations

US President Donald Trump has signed a memorandum permitting private firms to execute offensive cyber operations. The move raises new risks of retaliatory attacks and collateral system disruptions.

14 Aug 2026 3 min 







](/news/us-directive-private-firms-offensive-cyber-operations)[

![Adobe Commerce attacked immediately after session breach vulnerability](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/adobe-commerce-session-vulnerability-exploited-after-disclosure-1786684691416.png)

Breach Analysis 

### Adobe Commerce attacked immediately after session breach vulnerability

Security firm Sansec blocked attacks targeting Adobe Commerce immediately after disclosure. The flaw allows unauthenticated attackers to hijack sessions and customer data.

14 Aug 2026 4 min 







](/news/adobe-commerce-session-vulnerability-exploited-after-disclosure)[

![Cornelius faces legal investigation after alleged Cl0p cyber attack](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/cornelius-alleged-clop-ransomware-data-breach-1786684482605.png)

Breach Analysis 

### Cornelius faces legal investigation after alleged Cl0p cyber attack

Cornelius faces legal scrutiny following reports of a Cl0p ransomware breach in August 2026. Claims suggest thousands of gigabytes of corporate data were compromised.

14 Aug 2026 4 min 







](/news/cornelius-alleged-clop-ransomware-data-breach)[

![Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fdelta-rogue-wifi-defcon-2026.jpg)

Breach Analysis 

### Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust

Delta Air Lines is investigating an unauthorised Wi-Fi network broadcast aboard Flight 591 from Las Vegas to Atlanta, alongside a deauthentication attack that knocked passengers off the aircraft network. The lesson is not about aviation. It is about how easily a trusted connection can be impersonated.

13 Aug 2026 4 min 







](/news/delta-flight-rogue-wifi-deauth-attack-def-con-2026)[

![Ransomware Attacks Spike 20% in July While AI Steals the Headlines](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fransomware-spike-ai-distraction.jpg)

Breach Analysis 

### Ransomware Attacks Spike 20% in July While AI Steals the Headlines

Ransomware attacks jumped nearly 20 per cent in July, with 799 incidents logged globally. While AI dominates security headlines, finance, technology, pharmaceutical, medical billing and education organisations absorbed the sharpest increases.

12 Aug 2026 4 min 







](/news/ransomware-attacks-spike-july-2026-ai-distraction)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)