Origin Energy Data Breach 2026:
What You Need to Know
Origin Energy has confirmed that some customer data was accessed and disclosed without authorisation. The exact number of affected customers is not yet known. Here is what Origin has confirmed, what remains unverified, and the practical steps customers can take now.
Your personal risk from this breach
Sign in or create a free account to see your personalised risk score.
What Happened
How the Origin Energy Breach Unfolded
Before 22 July 2026
The date and method of the unauthorised access have not yet been disclosed. A person claiming to hold Origin customer records reportedly approached Australian media and claimed to have data relating to around two million customers. That number remains an attacker claim, not a figure verified by Origin.
22 July 2026
Origin publicly said it was investigating a potential security incident that may involve unauthorised access to customer data. It notified the Australian Cyber Security Centre and the Australian Federal Police, and engaged with the Office of the Australian Information Commissioner (OAIC).
23 July 2026
Origin confirmed that unauthorised access and disclosure of some customer data had occurred. It said the information may include names, addresses, dates of birth, phone numbers, account information, and limited payment identifiers. Origin said it was still determining the number of affected customers and would contact people once their involvement was confirmed.
This is an active investigation. The affected population, access method and full data set may change as Origin completes its review.
What Was Exposed
Customer Data Origin Says May Be Affected
Origin says the fields involved may vary by customer. It is still determining which customers and records were affected, so the categories below should not be read as applying to every Origin customer.
| Data Type | Risk Level | Who Was Affected |
|---|---|---|
| Name | High | Some affected customers; exact number not yet disclosed |
| Address | High | Some affected customers; exact number not yet disclosed |
| Date of birth | High | Some affected customers; exact number not yet disclosed |
| Contact phone number | High | Some affected customers; exact number not yet disclosed |
| Origin account information | Medium | Some affected customers; fields may vary by customer |
| Last four digits of a credit card | Medium | A subset of affected customers |
| Last three digits of a bank account | Medium | A subset of affected customers |
Risk levels are based on the OAIC guidance on personal information and the Australian Privacy Principles. Name, date of birth, address and phone are rated High here because their combination is commonly used to verify identity at banks, utilities and telecommunications providers. Partial payment digits are rated Medium because they cannot usually authorise a payment alone, but can strengthen impersonation.
Not reported as exposed so far
Origin has not reported full card numbers, full bank account numbers, passwords, passports, driver's licences or Medicare numbers among the affected fields. The investigation is continuing, so customers should rely on Origin's direct notification about their own record.
Company Response
What Origin Energy Has Done
“Customers trust Origin with their information, and I apologise for the impact this may cause.”
Actions reported by Origin
- Launched an urgent investigation into the incident
- Engaged the Australian Cyber Security Centre and Australian Federal Police
- Engaged with the OAIC
- Said it would contact customers when their involvement was confirmed
- Published an incident update for customers
What Now?
Steps You Can Take After the Origin Energy Breach
The combination of name date of birth address and account information can make a scammer sound convincing. These steps focus on verification, account security and financial monitoring.
Origin Account and Energy Scams
Scammers may refer to real account, property or billing details to gain trust.
Verify any Origin contact independently
Review your Origin account
~5 minPayment and Banking
Partial payment digits are not full credentials, but they can make impersonation more believable.
Review card and bank transactions
Do not disclose the missing digits
Email and Digital Identity
Secure the email account connected to Origin and reduce the chance of account recovery abuse.
Strengthen your email security
~5 minAvoid unnecessary password resets
Identity Protection
Name, date of birth and address together can support identity-verification fraud.
Consider a credit ban if your identity details were exposed
~20 minMonitoring and Reporting
Use trusted Australian support if you notice attempted fraud or identity misuse.
Not sure which of your accounts are affected?
In The Event Of helps you review breach exposure and work through a clear, prioritised response plan.
Are You Still at Risk?
The Hidden Danger: Compound Breach Exposure
The Origin breach may overlap with earlier Australian incidents. Repeated exposure can give criminals a more complete identity profile than any one breach provides.
How breach data compounds
Origin's confirmed categories include identity, contact, account and partial payment data. If the same person also appeared in Optus, Medibank or Latitude, separate data sets may combine those details with identity-document or health information, increasing the risk of convincing fraud.
- Optus (2022)9.8M records - contact and identity-document data
- Medibank (2022)9.7M records - identity and health data
- Latitude Financial (2023)14M records - identity-document and financial data
- Origin Energy (2026)Count unknown - identity, account and partial payment data
Frequently Asked Questions
Origin Energy Breach FAQ
How do I know if I was affected by the Origin Energy breach?
What information was exposed?
Were full credit card or bank account details exposed?
Were passwords or identity documents exposed?
Did the breach affect two million customers?
What should I do first?
Other Major Australian Data Breaches
Data from multiple breaches can be combined to increase identity fraud risk. Review these guides to understand your full exposure.
Partnered Health Data Breach 2026
Undisclosed records exposed
ACMI Data Breach 2026
~25,000 records exposed
Melbourne Film Festival Data Breach 2026
~26,782 records exposed
UWA Callista Student System Data Breach 2026
Undisclosed records exposed
University of Sydney Data Breach 2025
~27K records exposed
NYC Health + Hospitals Data Breach 2026
~1.8M records exposed
Australian Courts Data Breach 2026
Thousands of files records exposed
youX Data Breach 2026
~444K records exposed
Prosura Data Breach 2026
300K-500K records exposed
Canvas (Instructure) Data Breach 2026
~275M (claimed) records exposed
Booking.com Data Breach 2026
Undisclosed records exposed
McGraw Hill Data Breach 2026
13.5M records exposed
Crunchyroll Data Breach 2026
Undisclosed records exposed
Eurail Data Breach 2026
300K+ records exposed
Basic-Fit Data Breach 2026
1M records exposed
Under Armour Data Breach 2025
72M records exposed
Salesforce (ShinyHunters) Data Breach 2025
~1B records exposed
Allianz Life Data Breach 2025
2.8M records exposed
Workday Data Breach 2025
Undisclosed records exposed
Western Sydney University Data Breach 2025
10K records exposed
Genea Fertility Data Breach 2025
940K records exposed
DeepSeek Data Breach 2025
1M records exposed
Tangerine Telecom Data Breach 2024
232K records exposed
Australian Clinical Labs Data Breach 2022
223K records exposed
Qantas Data Breach 2025
5.7M records exposed
Optus Data Breach 2022
9.8M records exposed
Medibank Data Breach 2022
9.7M records exposed
Latitude Financial Data Breach 2023
14M records exposed
MyDeal (Woolworths) Data Breach 2022
2.2M records exposed
Guides to read next
In The Event Of is an Australian digital footprint manager that helps you find the accounts linked to your email, see your breach exposure, and work through a prioritised action plan. These guides walk through the steps:
Disclaimer: This guide is provided for general informational purposes only and does not constitute legal, financial, or professional advice. This is an active investigation, and information may change. In The Event Of Pty Ltd (ABN 38 687 352 647) is not affiliated with Origin Energy Limited. If you believe you have been affected, contact Origin and seek guidance specific to your circumstances.