Origin Energy has revealed that full bank account numbers belonging to about 60 customers were accessed during its July 2026 data breach, adding a significant new detail to a cyber incident affecting approximately 900,000 current and former customers.
The energy retailer says it has substantially completed its review of the information accessed and is finishing individual notifications to affected customers. A criminal investigation remains underway, while Origin says the compromised customer data has not been publicly leaked or disclosed.
What information was accessed?
The roughly 900,000 affected customers did not all have the same information exposed. Origin says compromised records contained different combinations of names, addresses, dates of birth, phone numbers, account information and details relating to customers’ personal circumstances.
Some records included the last four digits of a credit card or the last three digits of a bank account. The latest review found that a much smaller group — approximately 60 customers — had their full bank account numbers accessed.
Numbers associated with government concession schemes or programs were also accessed for approximately 15,000 customers. This distinction matters because the latest disclosure does not mean complete banking information belonging to all 900,000 affected people was exposed.
How the Origin Energy breach came to light
The incident emerged in July after an alleged hacker provided The Australian with a sample of 50 Origin customer records. According to ABC News, those records contained information including names, addresses, email addresses, dates of birth, phone numbers and billing histories.
After the information was provided to Origin, the company alerted authorities to a potential security incident. Origin later confirmed unauthorised access to customer information and estimated that approximately 900,000 current and former customers were affected.
Customers had separately reported delays receiving energy bills shortly before the breach was confirmed, but Origin said those billing issues were not connected to the cyber incident. This is separate from recent Origin electricity bill and daily supply charge changes affecting some Australian households.
Investigation linked to a Manila call centre
ABC News reported that authorities traced the intrusion to an Accenture-operated call centre in the Philippines and that the investigation has been linked to a former Accenture employee in Manila. Accenture provides call-centre services to Origin but declined to comment on the specific incident when approached by the ABC.
Origin chief executive Frank Calabria said the criminal investigation remains ongoing and that the company’s priority is completing notifications and supporting affected customers.
Origin says it has taken additional measures to strengthen its systems following the incident and continues working with government agencies and cybersecurity specialists. Customers can check the company’s official Origin Energy data security update for current information and support guidance.
Why full bank account numbers matter
A bank account number alone does not normally allow someone to simply withdraw money from an account. The concern is that complete financial information can become more useful when combined with a person’s name, date of birth, phone number or other compromised data.
That combination may help criminals make phishing, impersonation or social-engineering attempts appear more convincing. Similar concerns arise after other incidents involving stolen customer information, including the Craneware data breach involving employee and customer records.
Customers should therefore focus on the individual notification they receive from Origin rather than assuming everyone affected faces the same level of risk.
How the breach compares with other cyber incidents
The Origin incident is believed to be the largest known data breach involving an Australian energy retailer. EnergyAustralia experienced a cyber incident in September 2022 that exposed details belonging to hundreds of customers.
It also follows major Australian corporate breaches involving Optus and Medibank in 2022 and Qantas in 2025. Together, such incidents highlight how customer information held by large companies and external service providers can remain attractive to criminals long after it was originally collected.
Carnival Data Breach Exposes Personal Data of Nearly 6 Million Customers
Latitude Financial Fined $3.96M After Millions of Spam Breaches
What affected Origin customers should do
Anyone contacted by Origin should carefully check which information the company says was accessed. Customers whose full bank account numbers were involved should consider contacting their financial institution for guidance and monitor transactions for unfamiliar activity.
Unexpected calls, emails or text messages claiming to come from Origin or a bank should be treated cautiously. Customers should independently verify the sender through official contact channels and avoid supplying passwords, security codes or additional financial information in response to unsolicited requests.
The most important point is that the exposure varied substantially between customers. About 900,000 people were affected overall, but Origin’s latest review identifies only around 60 customers whose complete bank account numbers were accessed.















