Origin Energy Investigates Potential Customer Data Breach
Origin Energy, one of Australia’s largest energy retailers with over 4.7 million customers, is probing a suspected security breach that may have exposed customer data. The company confirmed the incident in a statement, acknowledging unauthorized access to some customer records but clarifying that financial details, such as credit card or bank information, were not believed to be compromised.
The breach came to light after a hacker reportedly shared a sample of 50 customer records with an Australian news outlet, containing names, addresses, emails, dates of birth, phone numbers, and billing history. While the claims remain unverified, Origin Energy has notified the Australian Cyber Security Centre (ACSC) and the Australian Federal Police as part of its urgent investigation.
The incident follows a string of high-profile cyberattacks in Australia, including breaches at Optus and Medibank in 2022, as well as a recent attack on Partnered Health, which exposed sensitive medical records. Origin Energy’s shares fell by 2.5% following the announcement, reflecting investor concerns over the potential fallout. The company has pledged to provide further updates as its investigation progresses.
Source: https://www.abc.net.au/news/2026-07-22/origin-energy-investigating-potential-data-breach/106944660
Origin Energy cybersecurity rating report: https://www.rankiteo.com/company/origin-energy
"id": "ORI1784694425",
"linkid": "origin-energy",
"type": "Breach",
"date": "1/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Potentially some of 4.7 million '
'customers',
'industry': 'Energy',
'location': 'Australia',
'name': 'Origin Energy',
'size': 'Over 4.7 million customers',
'type': 'Energy Retailer'}],
'data_breach': {'data_exfiltration': 'Hacker shared sample with news outlet',
'number_of_records_exposed': 'Sample of 50 records shared '
'(potentially more)',
'personally_identifiable_information': 'Names, addresses, '
'emails, dates of '
'birth, phone numbers, '
'billing history',
'sensitivity_of_data': 'Personally Identifiable Information '
'(PII)',
'type_of_data_compromised': 'Customer records'},
'description': 'Origin Energy is investigating a suspected security breach '
'that may have exposed customer data. The company confirmed '
'unauthorized access to some customer records but clarified '
'that financial details were not believed to be compromised. A '
'hacker shared a sample of 50 customer records with an '
'Australian news outlet.',
'impact': {'brand_reputation_impact': 'Investor concerns over potential '
'fallout',
'data_compromised': 'Names, addresses, emails, dates of birth, '
'phone numbers, billing history',
'identity_theft_risk': 'Potential risk due to exposed PII',
'payment_information_risk': 'None (financial details not '
'compromised)',
'revenue_loss': 'Shares fell by 2.5%'},
'investigation_status': 'Ongoing',
'references': [{'source': 'Australian news outlet'}],
'regulatory_compliance': {'regulatory_notifications': 'Australian Cyber '
'Security Centre '
'(ACSC)'},
'response': {'communication_strategy': 'Public statement and updates pledged',
'law_enforcement_notified': 'Australian Federal Police'},
'title': 'Origin Energy Potential Customer Data Breach',
'type': 'Data Breach'}