Origin Energy Hack: What Happened and Why the Three-Week Wait Matters

Origin Energy has confirmed that personal information belonging to about 900,000 current and former customers was stolen in a cyber attack. The company says it received an initial warning from the person claiming to be the hacker on 2 July 2026, but did not tell the public until 22 July 2026 The Guardian.
CEO Frank Calabria said the company received emails from someone claiming to have accessed customer records on 2 July. At that point, Origin did not take the message seriously because the person did not provide any proof that they had actually taken any data. On 22 July, Origin received confirmation that customer data had in fact been accessed, and then moved to tell the public. Calabria described the stolen material as "historical data" obtained without permission. Reporting from Reuters, ABC News Australia, and SBS News all confirmed the figure of about 900,000 affected people Reuters; ABC News; SBS News.
Origin Energy is Australia's largest energy retailer, with 4.8 million customer accounts. A "significant" portion of the 900,000 affected were former customers. The stolen data may include names, addresses, dates of birth, phone numbers, account information, the last four digits of a credit card, or the last three digits of a bank account number. Calabria said the company does not believe any information has been posted on the dark web — a hidden part of the internet often used for illegal activity.
The three-week gap between the warning and the public announcement raises questions about when a company should tell customers and regulators about a possible breach. Origin's reasoning is understandable: without proof that data had actually been stolen, the 2 July email could have been a fake threat trying to extort money, something large companies receive fairly often. Waiting for solid evidence before going public can make sense, because announcing a breach that turns out to be false can also cause harm.
The other side of the argument is just as clear. Three weeks is a long time for people to be unaware that their personal information may have been stolen. During that window, the risk of scams, identity theft, and other attacks could have been reduced if customers had been told sooner.
Calabria declined to answer a series of questions about the incident, citing an active criminal investigation. He would not say when the breach itself occurred, whether Origin staff were involved, whether a ransom was demanded or paid, or whether further data leaks are still possible. The company also dismissed reports that it had made a deal with the hacker to prevent further leaks, after The Australian published claims from a person saying they were responsible for the breach.
Origin Energy notified the Australian Cyber Security Centre about the incident Origin Energy. Calabria warned affected customers to watch out for suspicious activity and expect a higher risk of scams.
The stolen financial details — the last four digits of a credit card or the last three digits of a bank account — are not enough on their own for someone to steal money directly. But when combined with other stolen information like a date of birth and address, these small pieces can help a scammer answer security questions or pretend to be you when contacting a bank or service provider. Think of it like a lock: each piece of information is a single key cut. One cut does not open the door, but enough cuts together can create a working key.
The fact that account information was also stolen means scammers could send fake emails or text messages that include real details about your account, making them look convincing. This is the most common and effective way stolen customer data gets used.
The large number of former customers among those affected is also worth thinking about. Keeping personal data belonging to people who no longer use the company's services increases the amount of information that can be stolen, without providing any benefit to either the company or the customer. This is a well-known issue in privacy protection, and incidents like this tend to put more pressure on companies and regulators to limit how long they hold onto old data.
The questions Calabria would not answer — especially whether a ransom was demanded or paid, and whether someone inside the company was involved — will likely shape how regulators respond and whether affected customers could sue. Australia's privacy law requires companies to assess possible breaches "as soon as practicable" after learning about them, and to notify affected people and the Office of the Australian Information Commissioner if the breach could cause serious harm. The 20-day gap between the 2 July warning and the 22 July confirmation may face scrutiny under this rule, depending on when the company is considered to have actually become "aware" of the breach.
For now, the investigation is ongoing, affected customers are being notified, and the biggest questions — how the breach happened, whether someone inside the company was involved, and whether more data could still leak — remain unanswered.


