CSIDB logo
Incident

Origin Energy

Incident posture

Attack window
Jul 2026
Location
Australia
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-26 20:05

Linked entities

Victim
Origin Energy
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jul 2026
Disclosed
Jul 2026
Resolved
Pending

Summary

Origin Energy, an Australian power retailer serving about 4.8 million customers, disclosed that a cybersecurity incident exposed personal data of roughly 900,000 current and former customers, including names, dates of birth, phone numbers, addresses, account details and partial payment card or bank account numbers. The company said it started investigating a potential security threat after early signs seemed innocuous, but later evidence confirmed an intrusion. A individual claiming responsibility asserted that data from two million customers had been taken and threatened to release it unless a ransom was paid, later stating that an agreement had been reached with the company; the firm denied any such agreement and noted that the matter is under criminal investigation by authorities, limiting what it can share. Even if the stolen data is not made public, the company warned that the information could be used for scams.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Origin Energy Limited began investigating a potential security threat in early July 2026 after detecting unusual activity within its networks. Initial assessments indicated that the threat lacked credibility, prompting the company to continue monitoring without escalating the response. On July 22, 2026, new information emerged that confirmed an intrusion had occurred, leading the company to classify the event as a cybersecurity incident. The investigation revealed that unauthorized actors had gained access to systems containing customer information.

The compromised data included names, dates of birth, phone numbers, residential addresses, account details, and partial payment card or bank account numbers for approximately 900,000 current and former customers. An individual who claimed responsibility for the breach asserted that information from two million customers had been exfiltrated and threatened to release the data unless a ransom was paid. Subsequently, the same individual told The Australian newspaper that an agreement had been reached with Origin Energy and that no data would be made public. Origin Energy has not acknowledged any such agreement and has stated that the matter remains under criminal investigation by relevant authorities.

In a public statement, Origin Energy’s CEO Frank Calabria emphasized that the incident is a criminal matter subject to ongoing investigation, which limits the information the company can disclose at this time. The company acknowledged that, even if the stolen data is not released publicly, the information could be used by other threat actors to conduct scams against affected individuals. Origin Energy has not detailed specific containment or remediation steps beyond confirming the investigation and notifying the appropriate authorities.

Sources

Sources available to members: 1 source.

CSIDB