Back Open link
Reader View

Personal and banking details among customer data stolen in Origin Energy hack

www.theguardian.com · July 23, 2026 · 09:55

Hackers access Australian customers’ names, addresses, dates of birth, phone numbers and some bank account details, company says

Follow our Australia news live blog for latest updates

Get our breaking news email, free app or daily news podcast

Origin Energy customers’ addresses, phone numbers and partial bank account data have been accessed in a hack, the company has confirmed.

The firm has 4.8m customer accounts in Australia, providing electricity, fossil gas, LPG and internet services to homes and businesses.

Origin has yet to confirm which, and how many, customers had been affected. In a statement to the ASX on Thursday, it said it would tell customers once it confirmed whether they had been affected.

A person claiming to be the hacker has reportedly contacted media outlets with unverified claims that 2 million customers’ details were accessed.

Origin said data may include customers’ names, addresses, dates of birth, phone numbers and Origin account information, as well as the last four digits of a credit card, or the last three digits of a bank account.

The company said incomplete credit card or bank account information could not be used to make purchases or access accounts.

Origin first revealed the hack in a statement yesterday, saying it believed credit card or bank details had not been accessed. The company has not detailed how the hack occurred.

Origin’s chief executive, Frank Calabria, said the company was securing its systems and ensuring there was no further unauthorised access, working with independent cyber experts and authorities.

“I’m sorry this has happened,” Calabria said.

“Customers trust Origin with their information, and I apologise for the impact this may cause.”

Experts have warned customers could be vulnerable if the data is leaked and used for identity theft, or by scammers tricking people into believing they are representatives of real businesses.

Rumpa Dasgupta, a lecturer in cybersecurity at La Trobe University, said personalised records could be misused for physical robberies.

“In the wrong hands, this information could be exploited not only for highly targeted phishing campaigns but also to support physical crimes such as burglary by identifying vulnerable properties,” Dasgupta said.

Origin said the Australian Cyber Security Centre, the Australian federal police and the Office of the Australian Information Commissioner (OIAC) were all investigating.

Get the most important news as it breaks

The National Office of Cyber Security is leading the government’s response.

The AFP declined to comment on whether it had identified or communicated with Origin’s hackers.

The Australian reported it was first contacted by a person claiming to have hacked Origin on Tuesday, after which the newspaper alerted Origin, which made a statement on Wednesday.

An Origin spokesperson said the company had moved immediately to update the ASX as soon as it was aware of a potential incident.

The OIAC reported it received 1,205 data breach notifications in 2025, of which 716 were related to malicious or criminal activity.

Among the hacks was a leak of 5 million Qantas customers’ information in October, which prompted warnings scammers could cold call leaked phone numbers.

The federal privacy commissioner last week found Qantas did not make any omissions or failings in breach of the Privacy Act, in relation to the hack. The Australian federal police are investigating.

If you have something to share about this story, you can contact Guardian Australia’s news teams using one of the following methods:

The Guardian app has a tool to send tips about stories. Messages are end to end encrypted and concealed within the routine activity that every Guardian mobile app performs. This prevents an observer from knowing that you are communicating with us at all, let alone what is being said.

If you don’t already have the Guardian app, download it (iOS/Android) and go to the menu. Select ‘Secure Messaging’.

If you don't need strong security you can write to a Guardian Australia journalist using the details here. Click on a person to see their details.

For end to end encrypted email you can create a free Proton Mail account and email gaus.contact@protonmail.com.

You can use the encrypted messaging apps Signal or WhatsApp to message us at +61 490 758 250.

Finally, our guide at theguardian.com/tips lists several ways to contact us securely, and discusses the pros and cons of each.