Menu
Browse

Cyber Incident Victim: Origin Energy

Date

Jul 2026

Location

Australia

Status

Ongoing

Timeline
Discovered
Jul 2026
Disclosed
Jul 2026
Summary

Origin Energy disclosed that a cybersecurity incident exposed personal data of about nine hundred thousand current and former customers, including names, dates of birth, phone numbers, addresses, account details and partial payment card or bank account numbers. The company said it began investigating after early indications suggested the threat was not credible, but later evidence confirmed an intrusion. An individual claiming responsibility asserted that data from two million customers had been taken and threatened release unless a ransom was paid, later stating an agreement had been reached, a claim the company denied. The company's chief executive noted the matter is under criminal investigation by authorities, limiting further comment, and warned that the compromised information could be used for subsequent scams.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

Origin Energy Limited began investigating a potential security threat in early July, but the initially available information suggested the threat was not credible. On July 22, new information emerged that confirmed an intrusion into the company's systems. The investigation determined that threat actors had gained access to customer data, including names, dates of birth, phone numbers, addresses, account information, and partial payment card or bank account numbers. Origin Energy, which serves roughly 4.8 million customers, stated that the breach affects 900,000 current and former customers.

Cyber Incident Image

An individual claiming responsibility for the breach told media that information from two million customers had been obtained and warned that the data would be leaked unless a ransom was paid. The same individual later informed The Australian, behind a paywall, that an agreement had been reached with Origin Energy and that no data would be released. Origin Energy has not confirmed any such agreement, and its chief executive, Frank Calabria, emphasized that the incident is a criminal matter under investigation by relevant authorities, which limits the details the company can disclose. The company also acknowledged that, even if the stolen data is not made public, other threat actors could use the incident to conduct scams.

The breach exposes personal and financial details of nearly one million individuals. Origin Energy noted that the exposed data could be leveraged by other threat actors for scams. The company continues to work with law enforcement as part of the ongoing investigation and has not released further technical specifics about the attack vector or remediation steps. The situation remains under active review, with the company constrained by the ongoing criminal proceedings from providing additional information.

Sources
Sources available to members
1 source