{"id":64487,"date":"2026-07-23T17:06:28","date_gmt":"2026-07-23T21:06:28","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=64487"},"modified":"2026-07-23T17:06:28","modified_gmt":"2026-07-23T21:06:28","slug":"origin-energy-data-breach","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/origin-energy-data-breach\/","title":{"rendered":"Origin Energy Confirms Data Breach Exposing Customer Data"},"content":{"rendered":"<p>Australia\u2019s largest <a href=\"https:\/\/overcentral.com\/en\/elon-musk-apr-energy-grok\/\" title=\"Elon Musk buys $1 billion gas turbine firm APR Energy to power Grok\" data-iacss-internal=\"1\">energy<\/a> retailer, <a href=\"https:\/\/www.originenergy.com.au\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Origin Energy<\/a>, has confirmed a <a href=\"https:\/\/overcentral.com\/en\/assuranceamerica-data-breach-exposes-6-9-million-drivers-license-numbers\/\" title=\"AssuranceAmerica Data Breach Exposes 6.9 Million Driver&amp;apos;s License Numbers\" data-iacss-internal=\"1\">data breach<\/a> that exposed customers\u2019 personally identifiable information (PII), prompting an investigation alongside federal law enforcement. The company, which supplies electricity, natural gas, and broadband internet to 4.8 million customers, disclosed that an unknown threat actor gained unauthorized access to certain customer records. Origin is currently working to determine the full scope of the incident and has begun notifying impacted individuals directly.<\/p>\n<h2>What Data Was Exposed in the Origin Energy Breach<\/h2>\n<p>According to an official update from Origin, the compromised data includes full names, physical addresses, dates of birth, phone numbers, and account information. The breach also exposed partial financial details: the last four digits of credit cards and the last three digits of bank account numbers. The company emphasized that these financial fragments are incomplete and cannot be used to hijack accounts or initiate unauthorized charges. Origin CEO Frank Calabria has apologized to customers and stated that steps are being taken to prevent further unauthorized access. The company has reported the incident to the Australian Federal Police, the Australian Cyber Security Centre, and the <a href=\"https:\/\/overcentral.com\/en\/bhavin-turakhia-ai-office-neo\/\" title=\"Bhavin Turakhia bets $30M on AI Office alternative Neo\" data-iacss-internal=\"1\">Office<\/a> of the Australian Information Commissioner.<\/p>\n<h3>Hacker Claims to Hold Data of 2 Million Customers<\/h3>\n<p>Before Origin published its second statement, a threat actor using the alias &#8220;John Doe&#8221; contacted local media outlet 7news to claim responsibility for the breach. The hacker alleged to be in possession of PII for 2 million Origin customers and stated that they had attempted to contact Origin\u2019s security team, customer support, and board executives \u2014 reportedly receiving no response. The threat actor has set up a site where they threaten to leak the stolen data within two weeks unless Origin initiates contact via Signal to negotiate a resolution. These claims remain unconfirmed by Origin, which continues its investigation.<\/p>\n<h2>Why This Breach Matters for Energy Sector Security<\/h2>\n<p>The Origin Energy incident underscores the escalating threat to critical infrastructure and large consumer-facing utility providers. With annual revenue of $8.5 billion and a 20% stake in UK renewable retailer Octopus, Origin is a major player in the energy market. Breaches of this scale expose millions of individuals to risks of identity theft, phishing, and social engineering attacks. The exposure of partial financial data, while not directly usable for fraud, still provides threat actors with enough context to craft convincing targeted attacks. This incident aligns with a broader trend where attackers increasingly target energy and utility companies \u2014 not only for operational disruption but also for the rich consumer data they hold.<\/p>\n<h2>What Affected Customers Should Do Now<\/h2>\n<p>If you are an Origin Energy customer, take immediate steps to protect your accounts and personal information. First, change your Origin account password and ensure you use a strong, unique password that you do not reuse on other services. Enable two-factor authentication (2FA) on your Origin account and any other online accounts that support it. Monitor your bank and credit card statements closely for any unauthorized transactions, even small ones that might indicate a test charge. Consider placing a fraud alert or credit freeze with major credit reporting bureaus in your country. Be highly skeptical of unsolicited phone calls, emails, or text messages that reference the breach \u2014 threat actors will use this event to launch phishing campaigns. Use a reputable no-log VPN service when accessing sensitive accounts over public Wi-Fi to add an extra layer of encryption. Finally, consider using a zero-knowledge password manager to generate and store strong, unique passwords for every site, reducing the risk of credential stuffing attacks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Australia\u2019s largest energy retailer, Origin Energy, has confirmed a data breach that exposed customers\u2019 personally identifiable information (PII), prompting an investigation alongside federal law enforcement. The company, which supplies electricity, natural gas, and broadband internet to 4.8 million customers, disclosed that an unknown threat actor gained unauthorized access to certain customer records. Origin is currently [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":90513,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/64487.png","fifu_image_alt":"Origin Energy Confirms Data Breach Exposing Customer Data","footnotes":""},"categories":[349],"tags":[],"class_list":["post-64487","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/64487.png","fifu_image_alt":"Origin Energy Confirms Data Breach Exposing Customer Data","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/64487","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=64487"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/64487\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/90513"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=64487"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=64487"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=64487"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}