Origin Breach Puts Millions at Fraud Risk

The issue is not just that Origin was breached. The exposed names, dates of birth, contact details, account data, and partial payment information can be reused for fraud and impersonation, and patching or containment does not undo that exposure. Origin says some customer data was accessed and it is still working out the scale, while an alleged attacker claims theft of 2 million records and threatens to leak them unless paid. Origin has roughly 4.8 million customers, so that claim would put close to 40% of the base in scope and turns this into a large identity-and-payment exposure, not a routine notice. For responders, the lasting risk is follow-on misuse of customer records long after the initial intrusion is contained.

Part of the PlainSec briefing for 2026-07-28

Sources