The Origin Energy data breach investigation began after the company disclosed a potential security incident that may involve unauthorised access to some customers’ data. Origin says it does not currently believe credit card or bank details are included.
A person claiming responsibility has separately alleged that data relating to more than two million customers was obtained. That figure and the claimed data types have not been publicly confirmed by Origin. This article separates established facts from reported allegations and explains what customers can do now.
By Compuloop | Australian cybersecurity analysis | Published 22 July 2026
Breaking update at a glance
Confirmed: Origin is investigating possible unauthorised access to some customer data and has engaged the ACSC, AFP and OAIC.
Not confirmed: the alleged two-million-customer count, the complete list of data fields and the full extent of any access.
Official source: follow Origin Energy’s security incident update for new confirmed information.
What has Origin Energy confirmed?
On 22 July 2026, Origin Energy published an official update stating that it was urgently investigating a potential security incident that may involve unauthorised access to some customers’ data.
Origin said it did not believe the potentially affected information included customer credit card or bank details. That is an important distinction, but it does not mean customers should ignore the incident. Contact details, account information or transaction history can still make impersonation and phishing attempts more convincing if they are exposed.
The company also said it had engaged the Australian Cyber Security Centre and Australian Federal Police and had engaged with the Office of the Australian Information Commissioner. Origin said it would provide further updates as appropriate.
Current position: Origin has confirmed an investigation into a potential incident. It has not yet published a final affected-customer count or a definitive list of compromised data fields.
What is alleged — and what remains unverified?
7NEWS reported that a person claiming responsibility contacted its newsroom and alleged access to data associated with more than two million Origin customers. The report described claimed contact, account, address and payment-history information and an apparent attempt to pressure the company.
Those details are allegations from a person claiming responsibility. They should not be treated as proven merely because they are specific or accompanied by sample information. Investigators need to establish whether the data is genuine, current, complete, obtained from Origin and connected to the incident now under investigation.
Why the wording matters: “potential security incident”, “reported data breach” and “alleged two million customers” describe different levels of certainty. This article will not convert an attacker’s claim into a confirmed fact.
| Issue | Confirmed public information | Status |
|---|---|---|
| Security incident | Origin says it is investigating a potential incident that may involve unauthorised access to some customer data. | Confirmed investigation |
| Financial details | Origin says it does not believe the potentially impacted data includes customer credit card or bank details. | Origin’s current assessment |
| Authorities | Origin says it has engaged the ACSC and AFP and has engaged with the OAIC. | Confirmed by Origin |
| Two million customers | A person claiming responsibility told 7NEWS the dataset relates to more than two million people. | Allegation; not confirmed by Origin |
| Data types and extortion | 7NEWS reported claims involving contact, account, address and payment-history information, plus an apparent demand. Public verification remains incomplete. | Reported claim; investigation ongoing |
What data may be involved in the Origin Energy incident?
Origin has not yet released a final inventory of affected data. The company’s statement refers broadly to possible unauthorised access to some customer data and specifically says credit card or bank details are not believed to be included.
Media reports describe claims involving names, email addresses, phone numbers, dates of birth, account identifiers, property addresses and aspects of payment history. These categories remain reported claims unless Origin or investigating authorities confirm them.
Even without bank-card numbers, combined identity and account information can create risk. A scammer who knows a person’s energy provider, address, recent payment pattern or account reference can build a more credible story about an overdue bill, refund, meter problem, account verification request or service disconnection.
The immediate consumer risk is not limited to direct financial theft. It is the use of believable personal context to make the next scam harder to recognise.
What should Origin Energy customers do now?
There is no public confirmation that every Origin customer is affected. The sensible response is proportionate: follow official updates, tighten the accounts that protect your identity and be cautious about contact that uses the incident to create urgency.
- Use Origin’s official channels. Navigate directly to Origin’s update page or app instead of following links in unexpected email or SMS messages.
- Expect impersonation attempts. Be suspicious of urgent requests involving refunds, overdue accounts, disconnection threats, payment changes or identity verification. Review Origin’s scam guidance.
- Use a unique password. If your Origin password is reused anywhere else, replace it on every affected account. Do not wait for a criminal to test the same combination elsewhere.
- Protect your email account. Email is often the password-reset channel for other services. Enable multi-factor authentication and review recent sign-ins, devices and forwarding rules.
- Monitor accounts and bills. Check for unexpected changes, account notifications or transactions. Do not provide a one-time code to anyone who contacts you.
- Keep evidence and report harm. Save suspicious messages, contact your bank promptly if money is involved, and use official Australian phishing and ReportCyber guidance.
OAIC consumer guidance recommends acting according to the information involved, including changing email passwords and enabling multi-factor authentication when contact information is exposed, remaining alert to scams and contacting the relevant institution if financial or government identity information is affected.
Do you need to cancel a bank card now? Origin currently says it does not believe customer credit card or bank details are included. Do not make disruptive changes solely on an unverified claim; follow any specific notice from Origin or your financial institution and act immediately if you see suspicious activity.
Why phishing risk rises after a public breach claim
The Australian Cyber Security Centre explains that phishing uses messages that impersonate trusted organisations to steal information, credentials or money. A widely reported incident gives criminals a believable theme even if they never obtained the underlying dataset.
Customers may receive fake “security verification”, “refund”, “bill correction” or “account protection” messages. The safest habit is to stop, open the provider’s app or type its official website address yourself, then check whether the same alert exists inside the account.
Businesses should also warn reception, accounts payable and service-desk staff. Attackers can use public concern to target employees with fake supplier requests, invoice changes or calls claiming to be from the affected provider’s incident team.
What Australian businesses should learn from this incident
The Origin Energy data breach investigation is still developing, so it would be irresponsible to speculate about its technical cause. The wider control lessons, however, apply to every organisation that stores customer, employee or supplier information.
The ACSC’s guidance on securing customer personal data stresses that organisations should understand what they hold, limit access and apply stronger restrictions to privileged users. Risk rises as data is copied across customer platforms, analytics tools, support systems, exports and backups.
- Know what data exists: maintain an information asset register, including SaaS platforms, exports and historic records.
- Collect and retain less: define a business and legal reason for each field and delete information when the purpose expires.
- Protect identity: require MFA, remove stale accounts, separate administrators and tightly control customer-service access.
- Detect unusual access: centralise identity, endpoint, CRM, cloud and export logs with alerting for abnormal volume or behaviour.
- Plan communications: prepare an incident page, customer verification method, contact scripts and approval process before a breach.
- Test recovery and containment: rehearse credential resets, platform isolation, evidence preservation and clean restoration.
For a practical baseline, review Compuloop’s Essential Eight services, managed cybersecurity services and backup and recovery services. The right control set should reflect the systems and data your business actually depends on.
Australian data breach law: what the NDB scheme requires
Under the Privacy Act 1988, covered organisations must follow the Notifiable Data Breaches scheme. The OAIC’s June 2026 quick-reference guide describes four core stages: contain, assess, notify where required and review.
If an organisation suspects an eligible data breach but is unsure, the OAIC says it must take all reasonable steps to complete its assessment within 30 calendar days after becoming aware of the grounds for suspicion. When there are reasonable grounds to believe an eligible breach has occurred and serious harm is likely, affected individuals and the OAIC must be notified promptly unless an exception applies.
For business owners: the 30-day assessment period is not permission to wait. Containment, evidence gathering, risk assessment, legal advice and stakeholder preparation often need to run at the same time.
This is general information, not legal advice. Privacy, contractual, regulatory and critical-infrastructure obligations vary with the entity, sector, data and incident circumstances.
A practical first-24-hours checklist for a suspected breach
- Activate authority: appoint the incident lead, legal contact, technical lead and communications owner.
- Contain safely: revoke risky access, isolate affected services where practical and preserve volatile evidence.
- Secure identity: reset compromised credentials, protect privileged accounts and review active sessions and tokens.
- Establish facts: document what happened, when it began, which systems and data may be involved and what remains unknown.
- Engage specialists: involve cyber response, privacy/legal, insurance and relevant authorities based on the incident.
- Control messaging: publish only verified facts, give useful customer actions and make genuine contact easy to recognise.
- Watch for follow-on attacks: increase monitoring for phishing, account takeover, vendor impersonation and unusual exports.
- Record decisions: preserve a timeline of evidence, risk decisions, notifications and remediation for later review.
Is your breach response plan usable under pressure?
Compuloop can review identity, endpoints, Microsoft 365, cloud services, backups, logging and incident-response readiness, then turn the findings into a prioritised improvement plan.
Prepare before the next urgent call
Book a practical cyber incident-readiness review for your Australian business.
Request a cyber readiness review | Call 1300 007 613 | Email sales@compuloop.com.au
Questions Origin customers are asking
Has Origin Energy confirmed a data breach?
Origin has confirmed that it is investigating a potential security incident which may involve unauthorised access to some customer data. It has not yet published a final incident scope.
Were customer credit cards or bank details exposed?
Origin says it does not believe the potentially impacted data includes customer credit card or bank details. Customers should still monitor accounts and follow later advice if the assessment changes.
Were two million Origin customers affected?
The two-million figure is an allegation reported by news media from a person claiming responsibility. Origin has not publicly confirmed that number.
Should customers change their Origin password?
A unique password is sensible. If the Origin password was reused on another account, change it everywhere it was reused. Origin has not publicly confirmed that passwords were accessed.
Where can customers find verified updates?
Use Origin’s official incident update and official contact page. Avoid links in unsolicited messages.
Sources and editorial note
- Origin Energy, 22 July 2026: Potential customer data security incident
- 7NEWS, 22 July 2026: Report on the alleged cyber attack and claims
- OAIC: Act quickly if you’re affected by a data breach
- OAIC, 29 June 2026: Quick reference guide for responding to data breaches
- Australian Cyber Security Centre: Phishing guidance
- Australian Cyber Security Centre: Securing customer personal data
This developing-story analysis was checked against public information available on 22 July 2026. Compuloop has no access to Origin Energy systems, private investigation material or the alleged dataset. Criminal claims are described as allegations unless confirmed by Origin or investigating authorities. The article will be corrected or updated if material public facts change.





