Origin Energy believes personal information belonging to approximately 900,000 current and former customers was accessed during a major data security breach, increasing the risk of targeted scams and identity fraud.
The company has completed the initial phase of its review and is contacting affected people. Customer-support hours have been extended, while specialist identity and cybersecurity assistance will be offered to customers whose information was involved.
How can customers check if they were affected?
Origin has not released a public online checker or searchable list. The company says it will contact customers directly when it confirms their information was accessed.
People should monitor the email address, mobile number and postal address connected to their Origin account. Former customers are also affected, so anyone who has changed providers should watch for a notification.
Customers can sign in through the official Origin app or website to confirm their contact details. Suspicious messages should be checked by contacting Origin through independently verified details rather than links or numbers contained in the message.
What information was accessed?
The affected records may include:
- Names and residential or service addresses
- Dates of birth and telephone numbers
- Origin customer-account information
- The final four digits of credit-card numbers
- The final three digits of bank-account numbers
Origin says the incomplete financial details cannot be used alone to make purchases or access bank accounts. However, the combination of personal and account information could help criminals create convincing impersonation scams.
The company has not publicly confirmed that passwords, complete payment-card numbers, full bank-account numbers or government identity documents were accessed. The information involved may differ between customers.
Why the figure changed to 900,000
Originâs estimate follows its initial review of the incident. The approximately 900,000 affected people are among the companyâs roughly 4.8 million accounts across electricity, gas, LPG and internet services.
An earlier figure of two million customers came from an unverified claim attributed to a person purporting to be responsible for the breach. Origin did not confirm that number.
Timeline of the breach
Origin began examining a potential security threat in early July 2026. The company tried to establish its credibility and possible impact but said the information then available did not indicate a credible incident.
On July 22, new information suggested unauthorised access may have occurred. Origin responded by investigating, updating the market and notifying customers as a precaution.
Origin later confirmed that customer information had been accessed and disclosed without authorisation. On July 28, chief executive Frank Calabria announced the 900,000-customer estimate and apologised to those affected.
The figure and timeline were confirmed in an ABC News report on the Origin Energy breach.
What scams should customers watch for?
Criminals may use exposed names, addresses and account information in phishing emails, text messages or calls. They could claim a bill is overdue, a refund is available, a payment method has expired or an account needs urgent verification.
Customers should reject requests for passwords, complete card details or one-time security codes. Threats of immediate disconnection, pressure to transfer money and unfamiliar sign-in links are also warning signs.
What should customers do now?
- Verify any breach notification through Originâs official channels.
- Access the account through the official app or website.
- Change any password reused on another service.
- Enable multi-factor authentication where available.
- Monitor bank and card statements for unfamiliar transactions.
- Keep copies of suspicious messages and report attempted fraud.
Customers do not automatically need to replace a card because its final four digits were exposed. Anyone who detects an unauthorised transaction should contact their financial institution immediately.
Read More:
Who is investigating?
Origin says cybersecurity and forensic specialists are helping contain the incident and secure its systems. It is working with the Australian Cyber Security Centre, Australian Federal Police, Office of the Australian Information Commissioner and National Office of Cyber Security.
Calabria described the breach as a criminal matter. Origin has not publicly identified the attacker, confirmed the access method or said how long the unauthorised access continued.
A recent cyberattack that shut two Mackay Sugar mills showed how security incidents can affect physical operations, while the Carnival breach affecting nearly six million customers demonstrated the longer-term risks created when personal information is exposed.
Were Origin services disrupted?
Origin has not reported interruptions to electricity, gas, LPG or internet services. There is also no confirmed evidence that the exposed information has been publicly released or used to withdraw money from customersâ accounts.
Origin has not announced compensation or a class action related to the breach. Its shares were down more than 2 per cent by about 11am AEST on July 28 as investors assessed the incident.













