Breaches · 48 days ago
The issue is not just that Origin was breached. The exposed names, dates of birth, contact details, account data, and partial payment information can be reused for fraud and impersonation, and patching or containment does not undo that exposure.
Origin says some customer data was accessed and it is still working out the scale, while an alleged attacker claims theft of 2 million records and threatens to leak them unless paid. Origin has roughly 4.8 million customers, so that claim would put close to 40% of the base in scope and turns this into a large identity-and-payment exposure, not a routine notice.
For responders, the lasting risk is follow-on misuse of customer records long after the initial intrusion is contained.
3 sources covering this story
Origin Energy Data Breach Affects 900,000 Australians
The hacker claimed to have stolen the information of 2 million Origin Energy customers after breaching its systems.
Data Breach Confirmed After Australian Energy Giant Origin Is Hacked
A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it.
Australian energy provider Origin says data breach exposes client data
Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others.
The Record from Recorded Future
Major Australian energy supplier confirms customer data compromised
Origin Energy said it was working to figure out how many Australians were affected by a recent data breach.
Part of the PlainSec briefing for 2026-07-28