Contained Medium impact Data breach Checked 23h ago

Origin Energy data breach exposes 900,000 Australians

Origin Energy confirmed that someone gained unauthorized access to its customer systems and accessed data on about 900,000 current and former customers. A hacker claiming to be a former employee said they had stolen more than 2 million records and later claimed to have made a private deal with Origin not to leak the data. Origin said it received an earlier warning before confirming the breach. The investigation reportedly points to a former Accenture employee in Manila, where the outside company runs Origin's billing and customer support, rather than an Origin employee. This has not been officially confirmed. Origin has completed its review. It found that about 60 customers had their full bank account numbers accessed, about 100 customers had an ID document number accessed, and about 15,000 customers had government concession scheme or program numbers exposed.

Started
Jul 4, 2026
Latest activity
Aug 24, 2026
Attributed to
former Accenture employee in Manila, Philippines (unconfirmed, worked on Origin's outsourced billing andSuspected
Where
Australia
Sectors
Energy, Consumers
Scale
one company, about 900,000 current and former customers

Current status

No credible reporting or official update was found after Origin Energy's completed review statement dated 2026-08-24, as of 2026-09-10.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Who is behind it

The Australian Financial Review reported the alleged former employee may have intended to extort Origin using the stolen data, but this has not been proven and Origin has not officially confirmed the identity.

Impact

Names, home addresses, dates of birth, phone numbers, account details, and partial payment information, including the last four digits of a credit card or last three digits of a bank account, were exposed for most affected customers. As many as 60 customers had their full bank account numbers accessed, about 100 customers had an ID document number accessed, and roughly 15,000 customers had numbers linked to a government concession scheme or program exposed. Origin says no scanned ID documents were taken and none of the data has been leaked or disclosed publicly. The person under investigation is reported to have saved customer records to a personal laptop and kept the device after leaving their job, allegedly intending to use it to extort Origin, though this has not been proven.

What to do

Affected customers should watch for phishing emails, text messages, or calls referencing their Origin account and verify any contact from Origin through the company's official channels rather than links or phone numbers in messages.

Timeline

  1. Aug 24, 2026

    Origin Energy said its completed review found about 100 customers had an ID document number accessed and about 15,000 customers had numbers linked to a government concession scheme or program exposed, in addition to the 60 customers with full bank account numbers reported August 21. Origin said no scanned ID documents were taken and none of the data has been leaked publicly.

    Containedia.acs.org.au
  2. Aug 21, 2026

    The Australian Financial Review reported that Origin restricted internal staff access to customer files as part of security hardening while it finalizes its review of the breach.

    Containedafr.com
  3. Aug 21, 2026

    Origin disclosed that as many as 60 customers had their full bank account numbers accessed by the hacker in July, a step beyond the partial payment details reported earlier, though it said the data has not been leaked or disclosed publicly.

    Containedabc.net.au
  4. Aug 21, 2026

    Origin Energy said its review into the specific customer information accessed is now substantially complete and that it has contacted the roughly 900,000 affected current and former customers with support information.

    Containedoriginenergy.com.au
  5. Aug 18, 2026

    The Australian Financial Review reported that the breach investigation now centers on a former Accenture employee working in Manila, where Origin had outsourced billing and customer support. The person is alleged to have copied customer data to a personal laptop and taken it when leaving the job. The Australian Federal Police and CrowdStrike are involved in the investigation; the Australian Cyber Security Centre is not, because Origin has treated it as an employee matter. Origin and Accenture both declined to comment.

    Containedafr.com
  6. Aug 10, 2026

    ABC News reported that Origin's affected estimate remained 900,000 and that the company was still determining the final total and notifying affected customers.

    Containedabc.net.au
  7. Jul 29, 2026

    Origin CEO Frank Calabria said the company had changed security settings after the breach. ABC News reported that Origin's estimate remained about 900,000 affected customers.

    Containedabc.net.au
  8. Jul 28, 2026

    Origin Energy said about 900,000 current and former customers were affected and confirmed it had received an earlier warning about a possible threat before the breach was disclosed.

    Containedsecurityweek.com
  9. Jul 27, 2026

    The hacker, who described himself as a former Origin employee, claimed to have reached a private agreement with Origin not to leak the stolen data.

    Containedia.acs.org.au
  10. Jul 24, 2026

    A hacker claimed to have stolen data on 2 million Origin Energy customers and threatened to leak it.

    Activesecurityweek.com
  11. Jul 23, 2026

    Origin Energy confirmed unauthorized access had led to disclosure of customer names, addresses, dates of birth, phone numbers and account details.

    Activechannelnewsasia.com
  12. Jul 22, 2026

    Origin Energy said it was investigating a potential breach of customer data and did not believe payment card or bank details were affected.

    Emergingmsn.com

Sources

Related reports