Origin Energy Admits It Was Warned of Hack Three Weeks Before Public Disclosure

Origin Energy has confirmed that personal data of approximately 900,000 current and former customers was accessed in a cyber breach, and that it received an initial warning from the alleged attacker on 2 July 2026, three weeks before disclosing the incident publicly on 22 July 2026 The Guardian.
CEO Frank Calabria said the company received emails from someone claiming to have accessed customer records on 2 July but did not treat the communication as a credible threat at that stage because no proof of data exfiltration was provided. On 22 July, Origin received confirmation that customer data had in fact been accessed and moved to disclose the breach at that point. Calabria described the accessed material as "historical data" that appeared to have been obtained on an unauthorised basis. Corroborating reporting from Reuters, ABC News Australia, and SBS News all confirmed the figure of approximately 900,000 affected individuals Reuters; ABC News; SBS News.
Origin Energy is Australia's largest energy retailer, with 4.8 million customer accounts. A "significant" proportion of the 900,000 affected were former customers, according to the company. The accessed data may include names, addresses, dates of birth, phone numbers, account information, the last four digits of a credit card, or the last three digits of a bank account number. Calabria said the company does not believe any information has been placed on the dark web.
The three-week gap between the initial warning and public disclosure raises questions about the threshold at which a company is obliged, or at least expected, to notify customers and regulators of a potential breach. Origin's reasoning is straightforward on its face: absent proof of exfiltration, the 2 July email could have been a speculative extortion attempt, a category of communication that large corporations receive with some regularity. The decision to wait for corroborating evidence before going public is defensible from an incident-response standpoint, as premature disclosure of an unconfirmed breach can itself cause harm. The counterargument is equally clear: three weeks is a long window in which affected individuals remained unaware that their personal data may have been compromised, and in which the risk of downstream exploitation, phishing campaigns, and identity fraud could have been mitigated by earlier notification.
Calabria declined to answer a series of questions about the incident, citing an active criminal investigation. He would not say when the breach itself occurred, whether Origin staff played a role, whether a ransom was sought or paid, or whether the risk of further data leakage is ongoing or has been contained. The company also dismissed reports that it had reached a deal with the hacker to prevent further leaks, after The Australian published claims from a person asserting responsibility for the breach.
Origin Energy notified the Australian Cyber Security Centre about the incident Origin Energy. Calabria warned affected customers to remain vigilant for suspicious activity and to expect a heightened risk of scams, a standard but critical advisory given that the exposed data fields, names, dates of birth, phone numbers, and partial financial details, are sufficient to enable targeted social engineering attempts.
The partial nature of the financial data exposure, last four digits of a credit card or last three digits of a bank account, limits direct fraud risk in isolation. Combined with identity-level data such as date of birth and address, however, these fragments can serve as verification tokens in interactions with financial institutions or service providers, making them more valuable to attackers as enrichment data than as standalone fraud instruments. The presence of account information in the accessed dataset also raises the possibility of targeted phishing crafted with enough authentic detail to appear credible, which is typically the highest-yield use case for exfiltrated customer data of this type.
The "significant" proportion of former customers among the affected population is worth noting. Retention of data belonging to individuals who no longer have an active relationship with the company is a data-governance issue that intersects directly with breach risk. The longer personal data is retained after the business purpose for collecting it has lapsed, the larger the attack surface becomes without corresponding benefit to the organisation or the customer. This is a well-established principle in privacy-by-design frameworks, and incidents of this type tend to sharpen regulatory and public attention to retention practices.
The unresolved questions Calabria declined to address, particularly whether a ransom was sought or paid, and whether internal access played a role, will likely shape both the regulatory response and any potential class-action exposure. The Australian Privacy Act's Notifiable Data Breach scheme requires entities to assess suspected breaches "as soon as practicable" after becoming aware, and to notify affected individuals and the Office of the Australian Information Commissioner if the breach is likely to result in serious harm. The 20-day gap between the 2 July warning and the 22 July confirmation may draw scrutiny under that framework, depending on when the company is deemed to have become "aware" of a qualifying breach.
For now, the investigation is active, the affected customers are being notified, and the key questions about how the breach occurred, whether insider access was involved, and whether the leak risk is ongoing remain unanswered.


