Origin Energy Got Hacked — Here's What We Know So Far

Origin Energy confirmed on July 23, 2026 that hackers got into its systems and accessed customer personal details, including addresses, phone numbers, dates of birth, and partial banking information. Origin is one of Australia's largest energy retailers, and the breach could affect millions of people.
In a statement to the Australian stock exchange, Origin said the stolen data may include customers' names, addresses, dates of birth, contact phone numbers, Origin account information, and the last few digits of a credit card or bank account number. The company said these partial card or account numbers could not be used on their own to make purchases or access bank accounts. As of July 23, Origin had not confirmed which or how many of its 4.8 million customer accounts were affected (The Guardian).
Origin provides electricity, natural gas, LPG (a type of fuel), and internet services across Australia. Because so many people use Origin, even a partial data leak is a big deal. CEO Frank Calabria apologised and said the company was working with cyber security experts and authorities to secure its systems. Origin has not yet explained how the hack happened (The Guardian).
How the breach was discovered is unusual. The Australian newspaper was contacted by someone claiming to have hacked Origin on July 21, 2026. The newspaper then told Origin about it. This suggests the hacker may have gone to the media before Origin even knew its systems had been broken into. That is a pattern sometimes used by criminals who want to pressure a company into paying money by making the breach public (The Guardian).
Three Australian government agencies are now investigating: the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner (OAIC). The OAIC enforces a rule called the Notifiable Data Breaches scheme, which requires companies to tell people when their data has been stolen and could cause them serious harm. Origin published a customer update page and a statement for investors on July 22, 2026, before giving a fuller disclosure to the stock exchange the next day (Origin Energy; Origin Energy).
The regulatory backdrop is relevant. The OAIC received 1,205 data breach reports in 2025. Of those, 716 — about 59 percent — were caused by criminal activity. That means cyber attacks are the main source of data breaches in Australia. Origin's case is now part of that picture, and the number of people affected, once confirmed, will show how serious this incident is compared to others (The Guardian).
Several things are still unknown. Origin has not said how the hackers got in, whether they demanded a ransom, or whether they took more data than has been described. The company has been careful in its public statements, calling it a "potential" incident even while confirming that certain data was accessed. This is typical for companies during an active investigation, when legal teams need to avoid saying anything that could turn out to be wrong.
The concern here is what criminals can do when they combine different pieces of information. Even though the banking details are partial, the stolen names, addresses, dates of birth, and phone numbers give criminals enough to trick people. They could call or email Origin customers pretending to be from the company, using real personal details to sound convincing. They could also try to use this information for identity theft or to take over someone's phone number, a trick called a SIM-swap that lets them intercept text messages and verification codes.
For Origin's investors, the breach adds a new risk to watch. Australian companies can face fines under the Privacy Act, and large-scale breaches can lead to lawsuits from affected customers. How quickly Origin identifies and contacts the people affected will influence both the regulatory consequences and the legal risk.
The wider picture is that energy and utility companies are increasingly being targeted by hackers. Australia has a law called the Security of Critical Infrastructure Act that places extra cyber security requirements on important services like energy. Incidents like this are likely to bring attention from the Department of Home Affairs as well as the agencies already involved. Because privacy rules and critical infrastructure laws overlap, a breach at a company like Origin can trigger responses from multiple regulators at the same time.
Origin's next steps, including finding out which customers were affected and offering help such as credit monitoring, will determine the real-world impact of the breach. The company has said it will provide further updates as the investigation continues.


