Power Grid

Origin Energy — customer data breach

Disclosed 28 July 2026

Australia

What happened

Origin Energy, one of Australia's largest electricity and gas retailers, confirmed that an unauthorized party accessed and exfiltrated personal data of about 900,000 current and former customers, including names, addresses, dates of birth, contact details, account information and partial payment details (the last four digits of payment cards, or BSB and last three digits of bank accounts). Origin received emails on 2 July from an individual claiming to hold customer records, received proof of access on 22 July, and disclosed the incident publicly on 28 July. The company notified the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner. This is an IT customer-data breach at an energy retailer rather than a disruption of operational energy infrastructure; the record is kept for its energy-sector relevance and the marker is placed at Origin's Sydney headquarters.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Documented
Confidence
High
Infrastructure
Power Grid
Latitude
-33.8640°
Longitude
151.2020°

Attribution

Responsibility has not been established in the cited reporting.

Sources

  1. Origin Energy Data Breach Affects 900,000 AustraliansSecurityWeek; Bloomberg · Incident reporting