The Origin Energy data breach has exposed personal information of 900,000 current and former customers, making it one of the largest cyber incidents in Australia’s energy sector. The company admitted it was warned three weeks before going public, raising concerns about transparency and security protocols.
What Happened in the Origin Energy Hack?
Origin Energy, Australia’s largest energy retailer, revealed that a hacker accessed customer records on an unauthorized basis. The breach affects names, addresses, dates of birth, phone numbers, account information, and partial credit card or bank details. The company has 4.8 million customer accounts across electricity, gas, LPG, and internet services.
Get the #1 Wireless Door Camera
REOLINK Bestseller: 2K Weatherproof Video Doorbell, No Monthly Fees.
Timeline of Events
- 2 July: Origin receives emails from someone claiming to have accessed customer records, but no proof was provided at that time.
- 22 July: Origin obtains proof that customer data was accessed and announces the breach publicly.
- Late July: Affected customers begin receiving notifications, three weeks after the initial warning.
How Does This Compare to Other Australian Data Breaches?
| Incident | Affected Customers | Industry | Year |
|---|---|---|---|
| Origin Energy Hack | 900,000 | Energy | 2025 |
| Optus Breach | 9.8 million | Telecom | 2022 |
| Medibank Hack | 9.7 million | Health Insurance | 2022 |
| Latitude Financial | 14 million | Finance | 2023 |
While Origin’s breach is smaller in scale, it underscores the ongoing vulnerability of critical infrastructure and customer data across Australian industries.
What Data Was Compromised?
The exposed data includes names, addresses, dates of birth, phone numbers, account information, and the last four digits of credit cards or last three digits of bank accounts. Origin states that no data has been posted on the dark web yet, but customers remain at risk of scams and phishing attempts.
Key Takeaways for Affected Customers
- Be vigilant for suspicious emails, calls, or texts asking for personal information.
- Monitor bank and credit card statements for unauthorized transactions.
- Change passwords for Origin accounts and any other services using the same credentials.
- Consider placing a credit freeze with major credit bureaus.
- Enable two-factor authentication on all sensitive accounts.
What Origin Energy Is Doing
CEO Frank Calabria apologized and said the company is cooperating with law enforcement. Origin has secured its systems to prevent further breaches and is notifying affected customers. The company declined to answer whether a ransom was paid, or whether staff were involved.
FAQ
How do I know if I was affected by the Origin Energy hack?
Origin Energy is contacting affected customers directly. If you haven’t received a notification, you can check your account or contact Origin’s support line. The breach involves both current and former customers.
Should I change my credit card after the data breach?
Only the last four digits of credit cards were exposed – not full numbers. However, it is wise to monitor your statements closely and report any suspicious activity to your bank. If you see unauthorized charges, request a new card immediately.
Is my energy service affected by the hack?
No, the breach only involved customer personal data, not energy supply or billing systems. Your electricity, gas, or internet service continues as normal. However, be cautious of scammers claiming to need to “verify” your account due to the breach.
What steps is Origin taking to prevent future breaches?
Origin has stated it secured its systems immediately after the proof of data access. The company is working with cyber security experts and law enforcement to investigate the incident and implement stronger protections.
Stay updated with the latest news on the Origin Energy data breach and other cybersecurity incidents by following our Australia section. Protect your personal information and report any suspicious activity to the Australian Cyber Security Centre.