Origin Energy has confirmed that customer information has been accessed and disclosed following a cybersecurity incident, with the company working to determine the full scale of the breach and notify affected customers.
In an update issued on 23 July, Origin said it had confirmed “unauthorised access and disclosure of some customers’ data” after initially announcing it was investigating a potential security incident. The company has engaged independent cybersecurity specialists and is working alongside Australian government agencies as the investigation continues.
While Origin has not yet confirmed how many customers have been affected, it said impacted information may include customer names, residential addresses, dates of birth, phone numbers, account details, and limited payment information. The financial information exposed is restricted to the last four digits of credit cards or the last three digits of bank account numbers.
Origin said the incomplete financial information cannot be used to make purchases or directly access customer accounts.
Chief Executive Officer Frank Calabria apologised to customers, acknowledging the seriousness of the incident.
“Our priority is to support our customers and secure our systems. We sincerely apologise to our customers for the concern this incident will cause,” Calabria said.
The company has established dedicated support channels for affected customers and said it will directly contact individuals once it can confirm whether their personal information has been compromised. Customers are being advised to remain vigilant against phishing emails, phone calls and text messages that may seek to exploit the breach.
Origin said it is working closely with the Australian Cyber Security Centre (ACSC), the Australian Federal Police (AFP) and the Office of the Australian Information Commissioner (OAIC) as part of its ongoing response. Independent cybersecurity experts have also been engaged to investigate the incident, contain any remaining risk and strengthen security measures.
The incident adds to a series of cyber attacks affecting Australian organisations holding large volumes of customer data. Energy providers can be targeted due to the range of personal information they maintain, including identity details, billing information and customer account records.
Although Origin has indicated that the exposed payment information is incomplete, cybersecurity professionals warn that attackers can combine compromised personal information with social engineering techniques to conduct identity fraud or phishing campaigns. Customers are encouraged to independently verify any communications claiming to be from Origin and to avoid clicking links or providing personal information unless they are certain of the sender’s legitimacy.
Origin said its investigation remains ongoing and that additional information will be provided as more becomes known about the scope of the incident and the number of customers affected. The company said protecting customer information and restoring confidence in its systems remain priorities.

