Origin Energy has confirmed that a recent cyberattack led to unauthorized access and disclosure of customers’ personal and partial financial data, raising fresh concerns over the resilience of Australia’s critical infrastructure providers.
The incident, disclosed in a series of updates between 22 and 24 July 2026, affects an as-yet-unknown number of accounts across the country’s largest electricity and gas retailer.
On 22 July, Origin first notified customers and the market that it was investigating a “potential security incident” involving possible unauthorized access to some customer data, while initially asserting that credit card and bank details were not believed to be impacted.
Origin Energy Confirms Cyberattack
That position shifted a day later, when the company confirmed that a hacker had gained unauthorized access to customer records and that the incident had progressed from a suspected event to a confirmed data breach.
In its 23 July update, Origin acknowledged that exposed information includes names, residential addresses, dates of birth, contact phone numbers and account information for affected customers.
The company also confirmed that partial financial data was accessed, specifically the last four digits of some credit cards and the last three digits of some bank accounts linked to those customer profiles.
Although Origin has stressed that incomplete card and account numbers cannot be used on their own to perform transactions or directly access accounts, security experts note that this level of detail significantly increases the value of the dataset to cybercriminals.
When combined with core identity attributes such as name, address, and date of birth, partial financial identifiers can be weaponized in targeted phishing, account recovery fraud, and social-engineering attacks masquerading as legitimate Origin, bank, or government communications.
The attack has also raised questions over how the threat actor obtained access. Media reports indicate that a self-styled hacker claimed to have accessed up to two million customer records using an employee’s logon.
The incident appears to involve compromised credentials and misuse of legitimate access to extract data from internal systems, highlighting persistent identity and access management challenges in large enterprises.
Origin CEO Frank Calabria has publicly apologized, stating that customers “trust Origin with their information” and acknowledging the potential impact on those whose data has been exposed.
From a governance perspective, Origin has engaged the Australian Cyber Security Center, the Australian Federal Police and the Office of the Australian Information Commissioner, signaling that the breach is being treated as a significant cyber incident under Australia’s regulatory and critical infrastructure oversight frameworks.
Authorities and security advocates are urging customers to remain vigilant, monitor financial and energy accounts for suspicious activity, and treat unsolicited contact claiming to be from Origin with caution, particularly if it involves requests for credentials, one-time codes or payment details.
As investigations continue, the incident is likely to intensify pressure on critical infrastructure operators to harden identity controls, accelerate breach detection capabilities and improve transparency around cyber incidents that affect millions of citizens.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.