Personal and banking details among customer data stolen in Origin Energy hack
Origin Energy disclosed a data incident affecting an undetermined portion of its 4.8 million Australian customers. The breach exposed information such as names, addresses, dates of birth, phone numbers, and Origin account details. Some financial data was also accessed, including the last four digits of credit cards or the last three digits of bank accounts. The company emphasized that incomplete card or bank data cannot be used to complete purchases or transactions.
A person claiming responsibility approached media outlets with unverified assertions that roughly two million records were accessed. Origin has not confirmed the exact number of affected customers or provided details on how the intrusion occurred. Initially, the company stated that complete credit card or bank details were not compromised, but later acknowledged that some partial financial information had been accessed.
Origin’s leadership apologized for the incident and said the company is working with independent cybersecurity experts to harden its systems. The investigation involves multiple authorities, including the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner. The National Office of Cyber Security is coordinating the government’s response.
Security experts have cautioned that exposed personal information raises the risk of identity theft and targeted scams. A cybersecurity researcher warned that detailed customer records could be exploited for phishing campaigns and even physical crimes such as burglary targeting vulnerable properties. The breach contributes to a broader pattern of significant data incidents in Australia, with 1,205 breach notifications recorded in 2025, of which 716 involved malicious activity.