Origin Energy said attackers breached its internal network and stole customer information from its Australian operations. The company said the exposed data may include names, addresses, dates of birth, phone numbers, Origin account details, and partial payment information, including the last four digits of credit cards and the last three digits of bank accounts.
The energy provider has not confirmed how many customers were affected, but a person claiming responsibility reportedly told media outlets that data from 2 million customers was accessed. Origin said it has engaged independent cyber experts, is securing affected systems, and has reported the incident to the Australian Cyber Security Centre, the Australian Federal Police, the Office of the Australian Information Commissioner, and the National Office of Cyber Security, while preparing to notify impacted customers as they are identified.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Origin Energy disclosed that its recent data breach affected 900,000 current and former customers in Australia. The company said the exposed data included names, dates of birth, phone numbers, addresses, account details, and partial payment card or bank account numbers.
Troy Hunt's summary cites reports that Origin Energy and the threat actor came to an agreement after the breach, possibly involving payment or promises tied to deletion of the stolen data. The report also noted that any such arrangement would not guarantee the data was actually deleted.
A threat actor calling themselves 'John Doe' reportedly told local media they would leak allegedly stolen Origin Energy customer data within two weeks unless the company contacted them on Signal to negotiate. The actor also claimed responsibility for the breach.
A person claiming to be the hacker reportedly told media outlets that details from 2 million Origin Energy customers were accessed. Origin Energy said it had not yet confirmed how many customers were affected.
Origin Energy reported the incident to Australian authorities, including the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner; reporting also said the National Office of Cyber Security was involved in the response or investigation.
Origin Energy confirmed that attackers compromised its internal network and accessed customer data from its Australian operations. The exposed information may include names, addresses, dates of birth, phone numbers, account information, and partial payment data.
Origin Energy said it identified a cyber security incident involving malicious actors, launched an investigation with external cyber security experts, and took immediate steps to secure affected systems.
Origin Energy said it identified suspicious activity affecting portions of its customer information systems on July 22, 2026. The company later investigated the activity as a cybersecurity incident involving unauthorized access and data exfiltration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcetechrepublic.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceoriginenergy.com.au
Open source7news.com.au
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.