Origin Energy has confirmed that full bank account numbers, ID document numbers and government concession details were accessed in its July data breach, which affected approximately 900,000 current and former customers.
The latest findings do not mean 900,000 customers had banking information stolen. Origin says about 60 customers had full bank account numbers accessed, around 100 had an ID document number exposed, and approximately 15,000 had numbers linked to government concession schemes or programs accessed.
Origin has now substantially completed its customer-by-customer review, allowing it to provide affected people with more precise information about what was exposed.
What information was accessed?
For most affected customers, the accessed information included some combination of names, addresses, dates of birth, phone numbers, Origin account information and other details about personal circumstances.
Some records contained the last four digits of a credit card or last three digits of a bank account. Origin has said these incomplete financial details cannot by themselves be used to make purchases or access an account.
- About 60 customers: full bank account numbers were accessed.
- About 100 customers: ID document numbers were accessed.
- About 15,000 customers: government concession scheme or program numbers were accessed.
Origin says the ID exposure involved document numbers only and that scanned copies of identification documents were not affected.
Other contacts may also be affected
Some Origin customer records contained information about other contacts, potentially including names, phone numbers, dates of birth and email addresses. Origin says it will directly notify those people where possible and provide support.
How will customers know what was exposed?
Origin has already contacted approximately 900,000 affected current and former customers and is providing more detailed individual notifications.
Those notices will explain what information was accessed for each customer, practical steps they can take and the support available. The risk therefore differs depending on the information held in each person’s record.
Why the bank account finding matters
Earlier disclosures focused mainly on personal information and partial financial details. Origin’s latest review has now established that approximately 60 customers had their full bank account numbers accessed.
While that represents a small fraction of the 900,000 affected customers, it is a significant development because it confirms the breach reached complete financial information for some people.
Investigation linked to Manila call centre
The breach occurred in July 2026. Australian authorities have since traced the incident to an Accenture-operated call centre in Manila, according to Australian media reporting. Accenture provides call-centre services to Origin, and the investigation has been linked to a former Accenture employee.
The criminal investigation remains ongoing, so responsibility has not been finally established. Origin says it is working with the Australian Federal Police, Australian Cyber Security Centre, National Office of Cyber Security and the federal government.
Has the stolen information been leaked online?
Origin has said there is no confirmed evidence that the customer information accessed during the incident was subsequently publicly leaked or disclosed.
However, unauthorised access can still create risks. Genuine names, addresses, dates of birth, phone numbers and account information could potentially be used to make phishing calls, emails or text messages appear more convincing.
What should Origin customers do now?
Affected customers should carefully read their individual Origin notification to determine exactly what information was accessed.
Customers should monitor bank and card activity, remain cautious about unexpected communications claiming to come from Origin, banks or government agencies, and independently verify requests for passwords, security codes, payments or additional personal information.
Origin is providing affected customers with support that includes identity monitoring and 12 months of free credit monitoring. Customers can check Origin Energy’s official security incident updates for information and assistance.
Krispy Kreme Data Breach Settlement: Deadline to Claim Up to $3,500
Comcast Settlement 2026: Check Eligibility for Up to $10,000 in Xfinity Data Breach Claims
Origin breach adds to wider data security concerns
The incident adds to concerns about the volume of sensitive customer information held by major organisations and their service providers. The Carnival data breach affecting nearly six million customers similarly demonstrated how large cyber incidents can expose personal information on a significant scale.
The Craneware data breach involving employee and customer records also highlighted why determining exactly which records were accessed can be critical for people assessing their individual risk.
Executive bonuses reduced after the breach
The incident has also affected Origin’s executive remuneration. CEO Frank Calabria’s pay was reduced by approximately $357,000, while reductions for other executive management totalled about $607,000.
The board said the reductions reflected shared accountability, the number of customers involved and the importance of protecting customer information. Further financial consequences could be considered once investigations and reviews are complete.
For affected customers, the August 21 update makes one point particularly important: the level of exposure is not the same for everyone. Those whose full banking, ID or concession numbers were accessed should pay especially close attention to Origin’s individual notification and recommended protective measures.















