Origin Energy Data Breach (July 2026): What Happened and What Customers Should Do Now
- scam alert
- data breach
- Origin Energy
- phishing
- identity theft
- Australia
Developing story — last updated 22 July 2026 (AEST). This article is for general information only and will be updated as Origin Energy and investigators confirm more. Details attributed to the alleged hacker are claims that have not been independently verified. Always confirm anything about your own account directly with Origin through the official channels listed below — never through a link or phone number sent to you.
Australia's largest energy retailer is dealing with a potential mass data theft. On 22 July 2026, Origin Energy told the ASX it is investigating the Origin Energy data breach — described by the company as "a potential security incident which may involve unauthorised access to some customers' data" — after an alleged hacker claimed to hold personal records of around 2 million customers. Origin serves about 4.8 million customer accounts across electricity, gas, LPG and internet, so if you are (or ever were) an Origin customer, this page covers what's known, what data may be exposed, how to reach Origin safely, and the exact steps to protect yourself from the scam wave that follows every big Australian breach. If a suspicious "Origin" message has already landed in your inbox, you can run it through our free scam checker right now.
What happened: the breach at a glance
- Who: Origin Energy Limited (ASX: ORG), Australia's largest energy retailer with ~4.8 million customer accounts.
- What: Suspected unauthorised access to customer data. An alleged hacker — reportedly using the alias "John Doe" — claims to have records of about 2 million customers and sent a sample of 50 customer records to The Australian newspaper as proof.
- When: Disclosed publicly on Wednesday 22 July 2026, in an ASX announcement lodged around midday AEST and a statement on Origin's website.
- Claimed data: Names, home addresses, email addresses, dates of birth, phone numbers, account numbers and billing history. The scale of the claim is not yet verified.
- Not affected (per Origin): "We do not believe the impacted data includes customer credit card or bank details."
- Who's investigating: Origin, the Australian Cyber Security Centre (ACSC) and the Australian Federal Police; the Office of the Australian Information Commissioner (OAIC) has been engaged.
- Extortion angle: Media reports say the hacker set a roughly 14-day deadline to "settle the matter" before releasing the data — a classic extortion play.
Timeline of the Origin Energy cyber incident
- Before disclosure: The alleged hacker reportedly claims they first approached Origin's board, security team and customer-care channels privately, and went public only after getting no resolution. That's their claim, not an established fact.
- 22 July 2026 (morning): The Australian reports being contacted by the alleged hacker, who provided a 50-record sample of customer data; 7NEWS reports receiving similar contact by email.
- 22 July 2026 (~12:40pm AEST): Origin lodges its ASX announcement and publishes an update on its website confirming an urgent investigation, and says it has engaged the ACSC, the AFP and the OAIC.
- 22 July 2026 (afternoon): Origin shares close the morning down roughly 3%. Security experts, including Deakin University cyber security professor Damien Manuel, publicly characterise the reported demand as extortion — "Criminals being criminals, can you really trust they won't release it anyway?"
Origin says its investigation is happening "as a matter of urgency" and that it "will provide further updates as appropriate" on its official update page.
What data was exposed in the Origin Energy breach?
Based on the sample reportedly reviewed by journalists, the claimed dataset includes:
- Full names and residential addresses
- Email addresses and phone numbers
- Dates of birth
- Origin account numbers, property identifiers and billing history
Origin's position so far is that credit card and bank details are not believed to be involved, and no evidence has emerged that My Account passwords were taken. Even so, the combination above is more than enough for convincing phishing, identity takeover attempts and fraudulent credit applications — see our guide to what information scammers actually need for identity theft.
Important: until Origin confirms exactly whose data was accessed, treat "am I affected?" as unanswered. Nobody can tell you that yet — and anyone who calls, texts or emails claiming they can is almost certainly a scammer.
The real danger now: post-breach scams
After every major Australian breach — Optus and Medibank in 2022 are the playbook — the stolen data (and the headlines alone) fuel weeks of follow-up scams. Fake "Origin" refund and billing emails were already a recurring phishing theme in Australia before this incident; expect them to surge, now personalised with real names, addresses and bill amounts. Watch for:
🚩 "Origin compensation" or "breach refund" messages. Origin has not announced any compensation scheme. Any email, SMS or call offering a payout, refund or "goodwill payment" for the breach is a scam.
🚩 Fake breach-notification emails that look like Origin and ask you to "verify your account", "secure your data" or "reset your password" via a link. Origin's legitimate emails come from @originenergy.com.au, and its real websites are origin.com.au and originenergy.com.au — scammers have previously used lookalikes such as originnergy.com.au.
🚩 Calls quoting your real details. A caller who knows your name, date of birth and last bill isn't proof of legitimacy anymore — assume that information may be in criminal hands. Banks and Origin will never ask for passwords, one-time codes or remote access to your device. This is exactly how the phantom hacker "safe account" scam starts.
🚩 Disconnection threats. "Your power will be cut off today unless you pay" remains one of the most effective utility scams, and breach anxiety makes it land harder.
Unsure about any message? Paste it into our free scam checker or verify the caller against our scam phone number checker before you act.
What Origin Energy customers should do now — 8 steps
- Don't click links in any breach-related message. Type
originenergy.com.auinto your browser yourself, or use the official Origin app, to check announcements and your account. - Verify any "Origin" contact independently. Hang up and call Origin back on 13 24 61 (the number on your bill), not a number the caller gives you.
- Change your Origin My Account password to something long and unique, and change it anywhere else you reused it. Origin says it will never ask for your My Account password by phone or email.
- Turn on multi-factor authentication on your email account first (it's the master key to everything else), then on banking and other key services.
- Watch your bank and card statements. Origin doesn't believe payment details were taken, but treat any unexpected transaction or "bank fraud team" call with suspicion.
- Consider a credit report check or ban. You can get free credit reports and, if worried, place a temporary ban with the three bureaus (Equifax, Experian and illion) — Moneysmart explains how.
- Get free expert help if you see misuse. IDCARE, Australia and New Zealand's national identity and cyber support service, is free — call 1800 595 160.
- Report scam attempts. Forward fake Origin emails to hello@origin.com.au, report scams to Scamwatch, and report cybercrime with financial loss via ReportCyber. If you've already clicked or paid, follow our damage-control checklist immediately.
How to contact Origin Energy (official channels only)
Use only these channels — never a number or link from an unexpected message:
- Residential electricity & gas: 13 24 61
- Small business: 1300 661 544 · large business/Origin Zero: 13 23 34
- LPG: 13 35 74
- Official contact hub: originenergy.com.au/contact (includes current hours, chat and My Account)
- Breach updates: originenergy.com.au/update-july-2026
- Report a fake Origin email: forward it to hello@origin.com.au, then delete it
- Origin's own scam guide: How to tell a scam from a real Origin message
Phone numbers can change — Origin's contact page is always the authoritative list.
Official help and reporting contacts (Australia)
- IDCARE (free identity & cyber support): 1800 595 160 · idcare.org
- Scamwatch (National Anti-Scam Centre): scamwatch.gov.au
- ReportCyber / Australian Cyber Security Centre: cyber.gov.au · hotline 1300 CYBER1 (1300 292 371)
- OAIC (privacy regulator — your rights after a breach): oaic.gov.au
- Moneysmart (credit reports, bans, identity theft): moneysmart.gov.au
- Your bank: call the number on the back of your card at the first sign of unusual activity.
Not Origin's first incident
This is the second data incident Origin has confirmed in under a year. In 2025, Origin disclosed that a former employee had allegedly exfiltrated the details of more than 700 customers — including, in that case, some credit and debit card details — before the file transfer was detected. That incident was reported to the OAIC, police and the Australian Signals Directorate, and affected customers were offered credit monitoring, according to reporting by Cyber Daily. The two incidents are unrelated as far as public reporting shows, but together they explain why regulators are watching closely.
Frequently asked questions
Was Origin Energy actually hacked?
Origin has confirmed it is urgently investigating "a potential security incident which may involve unauthorised access to some customers' data". The claim that ~2 million records were taken comes from the alleged hacker and has not been verified. What's certain: journalists were shown a sample of 50 real-looking customer records, and Origin escalated to the ACSC, AFP and OAIC the same day.
How do I know if my data was exposed?
You can't yet. Origin has not published affected-customer numbers or begun individual notifications. Watch Origin's official update page and your email (checking the sender is genuinely @originenergy.com.au). Under Australia's Notifiable Data Breaches scheme, Origin must notify affected individuals and the OAIC if the breach is likely to result in serious harm.
Were credit cards or bank details leaked?
Origin says it does not believe credit card or bank details are included in the impacted data. Passwords haven't been mentioned in any reporting. Still, monitor statements — breach data is routinely combined with phishing to get the financial details scammers didn't steal.
Will Origin Energy compensate customers?
No compensation, refund or credit-monitoring scheme has been announced for this incident as of 22 July 2026. That means every "claim your compensation" message you receive right now is a scam. If Origin offers support later, it will be announced on originenergy.com.au — not via a link-laden SMS.
Should I change my Origin password?
Yes — as a precaution, change your My Account password to a long, unique one and enable MFA on your email. There's no evidence passwords were taken, but a breached email + date of birth combo makes credential-stuffing and account-recovery attacks easier.
How can I tell a real Origin message from a fake one?
Real Origin emails come from @originenergy.com.au and link only to origin.com.au or originenergy.com.au. Origin never asks for your password, full card number or remote access. When in doubt: don't click, call 13 24 61, or check the message with our free scanner — it flags breach-compensation lures, lookalike domains and known-reported scam contacts automatically.