Origin Energy Discloses Data Breach Affecting 900,000 Customers
On July 28, 2026, Origin Energy, a major Australian energy company, publicly confirmed a significant data breach impacting approximately 900,000 current and former customers.
Key points
- 900,000 current and former customers affected.
- Exfiltrated data includes names, addresses, dates of birth, phone numbers, account details, and partial payment information.
- Incident confirmed on July 22, 2026, with public disclosure on July 28, 2026.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
Organization
- Published
- Jul 28, 2026
- Updated
- Jul 29, 2026
- Confidence
- High
- Evidence
- 3 sources
Structured assessment
Signal analysis
This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.
Threat source
Watch internet-facing systems, credential abuse and exploit activity.
Business impact
- Impact area
- Confidentiality
- Likely asset
- User or customer data
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?
On July 28, 2026, Origin Energy, a major Australian energy company, publicly confirmed a significant data breach impacting approximately 900,000 current and former customers. The breach led to unauthorized access and exfiltration of personally identifiable information (PII), including names, addresses, dates of birth, phone numbers, account details, and partial payment information such as the last four digits of credit cards or the BSB and last three digits of bank accounts. Origin Energy first identified a potential security threat in early July 2026, which was initially not deemed credible. However, new information on July 22, 2026, confirmed a security incident had occurred, prompting immediate action and notification of authorities. An alleged hacker provided a media outlet with a sample of 50 customer records and screenshots of internal Origin Energy systems, corroborating the data exfiltration. The incident is currently under investigation by Australian authorities, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police, and the Office of the Australian Information Commissioner. The specific technical vector used for initial access remains undisclosed.
When was this signal reported?
Shadow Tier lists Jul 28, 2026 as the signal date.
Which organization is connected to this signal?
Originenergy is the organization connected to this public signal.
Explore OriginenergyWhich impact area is relevant?
This signal is connected to data exposure and breach intelligence based on its reported consequences.
Explore data exposure and breach intelligence