Origin Energy Data Breach Exposes Customer and Partial Card Details

Origin Energy Data Breach Exposes Customer and Partial Card Details

Origin Energy Data Breach Exposes Customer and Partial Card Details

Origin Energy confirms data breach; scope still being determined. Image: Unsplash

Origin Energy confirms hackers stole customer and partial payment-card data, but the number affected and the method of access remain unknown.

Jul 27, 2026
We may earn from vendors via affiliate links or sponsorships. This might affect product placement on our site, but not the content of our reviews. See our Terms of Use for details.

An Australian energy retailer has joined the country’s growing list of major cyberattack victims after confirming hackers accessed customer data, including partial banking information.

Origin Energy confirmed that hackers accessed and stole customer information after an unauthorized party sent samples of the allegedly stolen data to an Australian media outlet. The company said the exposed information includes names, addresses, dates of birth, phone numbers, and some account details.

While Origin Energy says no complete financial credentials were exposed, the combination of personal and partial financial information could still give attackers enough context to launch convincing phishing campaigns, impersonate victims, or commit identity fraud.

The company has not disclosed how many customers were affected, according to Reuters.

The breach comes as Australian organizations continue to face a wave of cyberattacks, particularly across critical and essential sectors. Origin Energy has not disclosed how the attackers gained access and says it is continuing its investigation alongside government agencies.

How the Origin Energy breach came to light

According to The Record, the incident first came to light after an individual claiming to have breached Origin Energy contacted The Australian and provided samples of what they alleged was stolen customer data. The Australian informed the company, prompting Origin Energy to launch an internal investigation.

The company initially described the incident as a “potential security incident” and said it did not believe customers’ bank or credit card details had been compromised.

Reuters reported that it later confirmed unauthorized parties had accessed and disclosed customer information. This includes personal details and limited financial identifiers, such as the last four digits of payment card numbers.

Following confirmation of the breach, the company’s CEO apologized to its over 4.8 million customers. According to the samples sent, the hacker claims that 2 million customer records were stolen, but the company has neither confirmed nor denied the figure. Instead, the company says that affected customers will be notified once it determines who was impacted by the breach.

While more information has yet to be released, likely due to the recency and active investigations from various government bodies, the company says it has begun securing its systems.

Advertisement

Must-read security coverage

Lessons beyond this breach

The Origin Energy incident is the latest in a string of cyberattacks against Australian organizations, another indicator that companies providing essential services remain attractive targets for threat actors.

Origin Energy’s role makes this breach particularly significant. The company serves about 4.8 million customers across Australia, meaning millions of households and businesses entrust it with personal and financial information simply to access essential utilities.

There is no evidence that the breach disrupted operations. Still, incidents involving critical infrastructure operators are increasingly viewed through that lens. They inevitably prompt questions about the security posture of organizations that underpin everyday life. That’s because a compromise of customer systems today can expose weaknesses that attackers may try to exploit tomorrow.

For customers, the immediate concern is the increased risk of phishing, identity fraud, and other scams using the stolen information.

For businesses and governments, the incident serves as another reminder that protecting critical infrastructure now extends beyond keeping services online — it also means safeguarding the sensitive data those services collect at massive scale.

Also read: 23andMe Agrees to $18M Settlement With 43 States Over 2023 Data Breach

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.