O

Origin Energy Data Breach 2026:
What You Need to Know

Origin Energy has confirmed that some customer data was accessed and disclosed without authorisation. The exact number of affected customers is not yet known. Here is what Origin has confirmed, what remains unverified, and the practical steps customers can take now.

Disclosed:22 July 2026
Records affected:Not yet confirmed
Risk level:High

Your personal risk from this breach

Sign in or create a free account to see your personalised risk score.

View My Risk

What Happened

How the Origin Energy Breach Unfolded

Before 22 July 2026

The date and method of the unauthorised access have not yet been disclosed. A person claiming to hold Origin customer records reportedly approached Australian media and claimed to have data relating to around two million customers. That number remains an attacker claim, not a figure verified by Origin.

22 July 2026

Origin publicly said it was investigating a potential security incident that may involve unauthorised access to customer data. It notified the Australian Cyber Security Centre and the Australian Federal Police, and engaged with the Office of the Australian Information Commissioner (OAIC).

23 July 2026

Origin confirmed that unauthorised access and disclosure of some customer data had occurred. It said the information may include names, addresses, dates of birth, phone numbers, account information, and limited payment identifiers. Origin said it was still determining the number of affected customers and would contact people once their involvement was confirmed.

This is an active investigation. The affected population, access method and full data set may change as Origin completes its review.

Sources: Reuters and ABC News

What Was Exposed

Customer Data Origin Says May Be Affected

Origin says the fields involved may vary by customer. It is still determining which customers and records were affected, so the categories below should not be read as applying to every Origin customer.

Data TypeRisk LevelWho Was Affected
NameHighSome affected customers; exact number not yet disclosed
AddressHighSome affected customers; exact number not yet disclosed
Date of birthHighSome affected customers; exact number not yet disclosed
Contact phone numberHighSome affected customers; exact number not yet disclosed
Origin account informationMediumSome affected customers; fields may vary by customer
Last four digits of a credit cardMediumA subset of affected customers
Last three digits of a bank accountMediumA subset of affected customers

Risk levels are based on the OAIC guidance on personal information and the Australian Privacy Principles. Name, date of birth, address and phone are rated High here because their combination is commonly used to verify identity at banks, utilities and telecommunications providers. Partial payment digits are rated Medium because they cannot usually authorise a payment alone, but can strengthen impersonation.

Not reported as exposed so far

Origin has not reported full card numbers, full bank account numbers, passwords, passports, driver's licences or Medicare numbers among the affected fields. The investigation is continuing, so customers should rely on Origin's direct notification about their own record.

Company Response

What Origin Energy Has Done

“Customers trust Origin with their information, and I apologise for the impact this may cause.”
Frank Calabria, Origin Energy CEO, 23 July 2026

Actions reported by Origin

  • Launched an urgent investigation into the incident
  • Engaged the Australian Cyber Security Centre and Australian Federal Police
  • Engaged with the OAIC
  • Said it would contact customers when their involvement was confirmed
  • Published an incident update for customers

What Now?

Steps You Can Take After the Origin Energy Breach

The combination of name date of birth address and account information can make a scammer sound convincing. These steps focus on verification, account security and financial monitoring.

Origin Account and Energy Scams

Scammers may refer to real account, property or billing details to gain trust.

Verify any Origin contact independently

Do not use links or phone numbers in an unexpected message. Open the Origin app, type the official website address yourself, or call a number printed on an existing bill. Origin, your bank and government agencies will not ask for passwords or one-time security codes.
Origin scam awareness

Review your Origin account

~5 min
Check contact details, authorised people, account activity and recent bills for changes you did not make. If anything looks unfamiliar, contact Origin using its official channels.

Payment and Banking

Partial payment digits are not full credentials, but they can make impersonation more believable.

Review card and bank transactions

Check the card or bank account used with Origin for unfamiliar activity. Turn on transaction notifications where available. Contact your bank using the number on your card or its official app if you see anything suspicious.

Do not disclose the missing digits

A caller may quote the leaked last digits and ask you to provide the rest 'for verification'. Do not complete a card or bank account number for an unsolicited caller, and never disclose a one-time code.

Email and Digital Identity

Secure the email account connected to Origin and reduce the chance of account recovery abuse.

Strengthen your email security

~5 min
Use a unique email password and enable multi-factor authentication. Review forwarding rules and connected applications, as attackers can use these to silently intercept billing and password-reset messages.

Avoid unnecessary password resets

Origin has not said passwords were exposed. Change your Origin password if it is reused elsewhere, weak, or if Origin directs you to do so through an authenticated channel. Do not follow an unexpected password-reset link.

Identity Protection

Name, date of birth and address together can support identity-verification fraud.

Consider a credit ban if your identity details were exposed

~20 min
If Origin confirms that your name, date of birth and address were all involved, a free credit ban can stop new credit being opened while you assess the risk.

Monitoring and Reporting

Use trusted Australian support if you notice attempted fraud or identity misuse.

Contact IDCARE or report to Scamwatch

IDCARE (1800 595 160) provides free identity and cyber support. Report scam attempts to Scamwatch.

Not sure which of your accounts are affected?

In The Event Of helps you review breach exposure and work through a clear, prioritised response plan.

Check My Email Free

Are You Still at Risk?

The Hidden Danger: Compound Breach Exposure

The Origin breach may overlap with earlier Australian incidents. Repeated exposure can give criminals a more complete identity profile than any one breach provides.

How breach data compounds

Origin's confirmed categories include identity, contact, account and partial payment data. If the same person also appeared in Optus, Medibank or Latitude, separate data sets may combine those details with identity-document or health information, increasing the risk of convincing fraud.

  • Optus (2022)9.8M records - contact and identity-document data
  • Medibank (2022)9.7M records - identity and health data
  • Latitude Financial (2023)14M records - identity-document and financial data
  • Origin Energy (2026)Count unknown - identity, account and partial payment data

Were you affected?

Find out in 30 seconds. Free to check.

Check My Email Free

No credit card required.

Frequently Asked Questions

Origin Energy Breach FAQ

How do I know if I was affected by the Origin Energy breach?
Origin has said it will contact customers once it confirms they were affected. The total number of affected customers is not yet known. Use contact details from Origin's official website or your existing bill rather than links or phone numbers in unexpected messages.
What information was exposed?
Origin says affected data may include a customer's name, address, date of birth, contact phone number and account information. For some customers it may also include the last four digits of a credit card or last three digits of a bank account. The exact fields may vary by customer.
Were full credit card or bank account details exposed?
Origin has reported limited payment identifiers: the last four digits of a credit card or last three digits of a bank account for some customers. It has not said that full card or bank account numbers were disclosed. These partial digits can still make impersonation scams more convincing.
Were passwords or identity documents exposed?
Origin has not listed passwords, passports, driver's licences or Medicare numbers among the information confirmed so far. Because the investigation is continuing, customers should rely on Origin's direct notification about their specific data and watch for updated official advice.
Did the breach affect two million customers?
A person claiming responsibility reportedly said they held around two million Origin customer records. Origin has not verified that number and is still determining the affected population. It should therefore be treated as an unverified attacker claim, not a confirmed breach count.
What should I do first?
Be alert for calls, texts or emails that use real Origin, billing or address details to build trust. Do not disclose one-time codes, passwords or complete payment details. Contact Origin through its official website or a number printed on an existing bill, review your payment accounts, and secure the email account connected to Origin with a unique password and multi-factor authentication.

Other Major Australian Data Breaches

Data from multiple breaches can be combined to increase identity fraud risk. Review these guides to understand your full exposure.

Partnered Health Data Breach 2026

Undisclosed records exposed

High

ACMI Data Breach 2026

~25,000 records exposed

High

Melbourne Film Festival Data Breach 2026

~26,782 records exposed

High

UWA Callista Student System Data Breach 2026

Undisclosed records exposed

Medium

University of Sydney Data Breach 2025

~27K records exposed

High

NYC Health + Hospitals Data Breach 2026

~1.8M records exposed

Critical

Australian Courts Data Breach 2026

Thousands of files records exposed

Critical

youX Data Breach 2026

~444K records exposed

High

Prosura Data Breach 2026

300K-500K records exposed

High

Canvas (Instructure) Data Breach 2026

~275M (claimed) records exposed

Medium

Booking.com Data Breach 2026

Undisclosed records exposed

High

McGraw Hill Data Breach 2026

13.5M records exposed

High

Crunchyroll Data Breach 2026

Undisclosed records exposed

High

Eurail Data Breach 2026

300K+ records exposed

High

Basic-Fit Data Breach 2026

1M records exposed

High

Under Armour Data Breach 2025

72M records exposed

High

Salesforce (ShinyHunters) Data Breach 2025

~1B records exposed

High

Allianz Life Data Breach 2025

2.8M records exposed

High

Workday Data Breach 2025

Undisclosed records exposed

Medium

Western Sydney University Data Breach 2025

10K records exposed

High

Genea Fertility Data Breach 2025

940K records exposed

Critical

DeepSeek Data Breach 2025

1M records exposed

Medium

Tangerine Telecom Data Breach 2024

232K records exposed

High

Australian Clinical Labs Data Breach 2022

223K records exposed

Critical

Qantas Data Breach 2025

5.7M records exposed

High

Optus Data Breach 2022

9.8M records exposed

Critical

Medibank Data Breach 2022

9.7M records exposed

Critical

Latitude Financial Data Breach 2023

14M records exposed

Critical

MyDeal (Woolworths) Data Breach 2022

2.2M records exposed

High

Guides to read next

In The Event Of is an Australian digital footprint manager that helps you find the accounts linked to your email, see your breach exposure, and work through a prioritised action plan. These guides walk through the steps:

Disclaimer: This guide is provided for general informational purposes only and does not constitute legal, financial, or professional advice. This is an active investigation, and information may change. In The Event Of Pty Ltd (ABN 38 687 352 647) is not affiliated with Origin Energy Limited. If you believe you have been affected, contact Origin and seek guidance specific to your circumstances.