Origin Energy data breach exposes millions of customers
Origin Energy, Australia's biggest energy retailer, confirmed that an unknown attacker broke into its systems and accessed customer records. The exposed data includes names, addresses, birth dates, phone numbers, account details, and partial bank and credit card numbers.
- Report priority
- High
- Victim
- Origin Energy
What is known
An unidentified attacker gained unauthorized access to Origin Energy's customer database and copied personal records before a person calling themselves "John Doe" contacted media outlets to announce the theft.
What to do
Origin Energy is directly contacting customers whose data was exposed, so check for a notification email, letter, or call from Origin Energy, or log into your Origin account for any security alert. There is no public list or lookup tool readers can search themselves.
Origin Energy says the exposed card and bank details are only partial digits and cannot be used to make unauthorized transactions, but affected customers should follow the specific guidance and support offered in Origin Energy's direct notification and watch for phishing attempts that reference their real name or address.
Reported details
A person calling themselves "John Doe" contacts media outlets and claims to hold data belonging to 2 million Origin Energy customers. They threaten to leak the stolen records unless their demands are met. Origin Energy investigates, confirms an unknown attacker did access customer data, and reports the incident to the Australian Federal Police, the Australian Cyber Security Centre, and the Office of the Australian Information Commissioner.
Origin Energy has not published how the attacker got in, only that unauthorized access to its customer data occurred. The confirmed exposure covers full names, physical addresses, dates of birth, phone numbers, account details, and partial financial identifiers (last four digits of credit card numbers, last three digits of bank account numbers). The company says these partial numbers cannot be used for fraudulent transactions on their own.
The breach became public after an actor using the alias "John Doe" contacted media claiming to hold records on 2 million customers and threatening to leak them. Origin Energy has notified the Australian Federal Police, the Australian Cyber Security Centre, and the Office of the Australian Information Commissioner, and is contacting affected customers directly.
References
- bleepingcomputer.com · chick-fil-a-data-breach-affects-more-than-13-000-customers BleepingComputer
- securityweek.com · data-breach-confirmed-after-australian-energy-giant-origin-is-hacked SecurityWeek
- securityweek.com · chick-fil-a-accounts-get-fried-in-credential-stuffing-attack SecurityWeek
- gbhackers.com · australian-energy-giant-origin-confirms-data-breach GBHackers
- infosecurity-magazine.com · lidl-notifies-customers-of Infosecurity Magazine
- neuracybintel.com · ernst-and-young-discloses-data-breach-via-compromised-third-party-support-system NeuraCybIntel
- neuracybintel.com · lidl-online-shop-data-breach-exposes-customer-information-across-three-european-countries NeuraCybIntel
- neuracybintel.com · kddi-data-breach-exposes-email-addresses-and-passwords-of-over-12-million-users-across-japanese-isps NeuraCybIntel
- neuracybintel.com · medtronic-data-breach-notifications-reach-millions-what-patients-need-to-know-about-the-april-2026-cyber-incident NeuraCybIntel
- securityweek.com · upbound-group-says-data-breach-led-to-13-million-in-fraudulent-contract-losses SecurityWeek
- bleepingcomputer.com · ontrac-notifies-customers-of-data-breach-after-network-hack BleepingComputer