Australian Energy Giant Origin Victim of Cyberattack
Australia's largest energy provider, Origin Energy, has confirmed a cyberattack that leaked customer data. Attackers claim to have stolen the data of 2 million customers.
What Happened
Origin Energy, one of the largest players in Australia's energy sector, has officially confirmed it suffered a cybersecurity breach that exposed customer data. The company, which provides electricity, natural gas, and internet services to millions of customers, announced that an unknown threat actor gained unauthorized access to its systems and stole personal information. This development has sent shockwaves through the country's cybersecurity landscape.
Origin Energy first notified the public on July 22, 2026, that it had launched an investigation into "a potential security incident that may involve unauthorized access to some customers' data." This initial announcement raised concerns among customers and signaled that the company was working to understand the scope of the incident. Just a day later, on July 23, an update clarified the severity of the situation, confirming it was indeed a data breach. The company has a broad customer base of 4.8 million and is currently working to determine exactly how many customers were affected. It has committed to reaching out to affected customers through individual notifications to inform them of the risks.
The fact that Origin, a company with annual revenues of $8.5 billion and listed on the Australian Securities Exchange (ASX), has fallen victim to such a major cyberattack raises serious questions about the cyber resilience of critical infrastructure companies in the country. The company is also an international player, holding a 20% stake in the UK's renewable energy retailer, Octopus.
Adding to the seriousness of the incident, local media outlet 7news reported that before Origin's second statement, a threat actor identifying as "John Doe" contacted them to claim responsibility for the attack. This individual took the claims a step further, alleging to be in possession of data belonging to 2 million Origin customers. The threat actor claimed to have tried to contact the company's security teams, customer support, and even board members without receiving a response. This claim could spark debates about the effectiveness of the company's incident response procedures. The attacker also reported setting up a website where they threatened to leak the stolen data in two weeks if their demands are not met. This transforms the event from a simple data leak into a potential case of ransom and extortion.
What Data Was Stolen
According to the official statement from Origin Energy, the data potentially accessed by the cyberattackers includes highly sensitive and personal information. The company listed the following types of potentially exposed data:
- Full Name: The most basic information used to verify customers' identities.
- Physical Address: Customers' home or business addresses.
- Date of Birth: A critical piece of data for identity theft and fraud.
- Phone Number: Can be used for phishing and social engineering attacks.
- Account Information: Information such as the customer's account number with Origin Energy.
- Last Four Digits of Credit Card: Insufficient to make a payment on its own, but increases the risk of fraud when combined with other information.
- Last Three Digits of Bank Account: Like the credit card information, this is an incomplete piece of data but can be a valuable clue for fraudsters.
The company specifically emphasized that the leaked financial information is "incomplete" and cannot be used on its own to take over accounts or make unauthorized payments. While this statement aims to mitigate the risk of direct financial loss for customers, cybersecurity experts warn that even such partial information can be dangerous. Attackers could use these pieces of information to call customers, impersonate bank or Origin officials, and ask them to complete the missing details. Such sophisticated social engineering attacks could turn partial data into a full-blown financial disaster.
The combined leak of full names, addresses, and dates of birth is a virtual invitation for identity theft. Malicious actors could use this information to apply for new credit cards, open bank accounts, or misuse government services in the customers' names. Therefore, the consequences of the breach could be not only financial but also personal and legal.
How Did the Attack Happen
Origin Energy has not yet provided any technical details about the attack to the public. Critical questions such as how the threat actors breached the systems, what security vulnerability was exploited, or how long the attack was ongoing remain unanswered for now. Companies often refrain from sharing technical details until the forensic investigation they launch after such incidents is complete. The primary reason for this is to protect the confidentiality of the investigation and to avoid giving attackers clues about other potential weaknesses in their systems.
The identity or affiliation of the actor named "John Doe" behind the attack also remains a mystery. It is unknown whether this name represents an individual or an organized cybercrime group. The attacker's direct contact with the media and the establishment of a leak site for extortion suggest a financially motivated attack. However, there is no clear information on whether a ransom has been demanded or what the attacker wants from the company.
Who Is Affected
Those directly affected by the data breach are current and potentially former customers of Origin Energy. The company has a total of 4.8 million customers, which highlights the vast potential scope of the impact. The company stated that the process of identifying which customers' data was leaked is ongoing. Therefore, anyone who is or has been an Origin customer is advised to assume they are at risk and take necessary precautions.
If the threat actor's claim of holding data for 2 million customers is true, it means that nearly half of the company's customer base has been affected by this breach. This figure would make it one of the largest data breaches in Australian history.
What You Can Do
If you are an Origin Energy customer, you should act immediately to protect yourself against the possibility of your data being compromised. Here are the steps you can take:
- Change Your Password: Immediately change your Origin Energy account password. If you use the same password on other platforms, be sure to change those as well. Always use strong and unique passwords.
- Be Wary of Phishing Attacks: Attackers can use your stolen name, address, and account information to send you personalized and convincing phishing emails or SMS messages (smishing). Do not trust any communication claiming to be from Origin Energy that asks for your personal information or password. Companies generally do not request such information via email.
- Be Alert for Phone Scams: Your leaked phone number means you could be targeted by voice phishing (vishing) attacks. Be skeptical of anyone who calls you claiming to be from Origin, your bank, or another institution. If they ask for information like the rest of your credit card or bank account number, hang up immediately.
- Monitor Your Financial Activity: Regularly check your bank and credit card statements. Report even the smallest unfamiliar or suspicious transactions to your bank immediately.
- Follow Official Channels: Keep up with official announcements from Origin Energy. The company has stated it is providing a dedicated support portal and resources for affected customers. Take advantage of the support services offered through these channels.
What the Company Is Saying
Origin Energy took swift steps to inform the public and manage the crisis after the incident came to light. Origin CEO Frank Calabria apologized to customers for the exposure of their sensitive data. Calabria stated that the company is taking the necessary steps to block further unauthorized access and make its systems more secure.
The company's statement emphasized that customers confirmed to be affected will be contacted directly and offered support through a dedicated portal and related resources. This support package typically includes services such as identity theft protection or credit monitoring.
Origin also announced that it has reported the incident to relevant government agencies, including the Australian Federal Police (AFP), the Australian Cyber Security Centre (ACSC), and the Office of the Australian Information Commissioner (OAIC), and will continue to cooperate with them throughout the investigation. This demonstrates compliance with legal obligations and that the incident is being treated with national-level seriousness.
Source
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.