What happened
On July 28, 2026, Origin Energy said the initial phase of its review found that information belonging to approximately 900,000 current and former customers was accessed. The company said it is contacting affected customers, has extended support hours and is working with cybersecurity and forensic specialists. Origin stated that the incident is contained, but the public update did not identify the intrusion vector, access period or responsible actor. No actor attribution has been established.
On July 23, 2026, Origin confirmed unauthorised access and disclosure of customer data. Potentially affected fields include names, addresses, dates of birth, telephone numbers, account information, the last four digits of a credit card or the last three digits of a bank account. Origin said the incomplete payment information cannot be used by itself to make purchases or access accounts. No hashes, domains, IP addresses, malware names or detection signatures were published. The cited source did not publish the precise timeline detail described as Intrusion vector and access period not disclosed.
Why this matters now
The affected count creates a substantial operational task spanning notification, identity verification, inbound support, fraud monitoring and regulatory engagement. Current and former customer information can give criminals credible details for tailored phishing, account-recovery fraud and impersonation even when complete financial credentials are unavailable. Customer communications must therefore be verifiable and must not train recipients to click untrusted links or disclose additional information.
The inclusion of former customers raises questions about retention, archival access and segmentation. Security leaders should determine whether inactive records were stored in the same systems and protected by the same controls as active accounts. The response should also establish whether suppliers, analytics platforms or customer-service systems received copies of the affected data and whether their logs can support the investigation.
The decision for security leaders
Privacy, legal and incident response should maintain one reconciled record of affected people, accessed data fields, notification status and jurisdiction. Customer operations must use authenticated channels and scripts that explain what Origin knows, what remains under investigation and how customers can validate contact without surrendering more personal information.
The forensic work must produce an evidenced intrusion vector, access period, affected-system list and containment basis. Data owners should review retention requirements for former-customer records and document deletion, anonymisation or restricted archival decisions. Fraud teams should monitor for Origin-themed lures and share confirmed patterns with customer support and relevant authorities.
Evidence of closure
- Notification records reconcile to the final affected population.
- Forensic findings document the intrusion vector and access period.
- Data mapping identifies every accessed field and system.
- Regulators receive complete, internally approved incident submissions.
The Security.io assessment
Origin’s estimate is an initial figure, not a final forensic count. The company has confirmed access, disclosure and affected data categories, so breach status is not dependent on the hacker’s larger public claim reported elsewhere. Security.io does not treat unverified criminal claims about a higher count as confirmed evidence.
The disclosed payment fragments reduce direct transaction risk but can still assist identity verification bypasses when combined with names, addresses, birth dates and account information. Closure therefore requires more than notification. Origin needs to demonstrate containment, explain the access path, identify all replicated data stores and address why former-customer information remained exposed to the compromised environment.
Questions for the morning meeting
- Why was former-customer data still retained and accessible?
- Which controls failed to prevent or detect the access?
- Can customers distinguish genuine notifications from phishing?
- What assurance supports containment?