Fraud & Consumer Rights

Origin Energy confirms cyber breach affecting millions of Australian customers

Origin Energy is investigating unauthorized access to customer data affecting its 4.8 million account holders, potentially making it one of Australia's largest cyberattacks alongside previous breaches at Optus and Medibank.

110177141-0-image-m-16_1784709382612.jpg
110177141-0-image-m-16_1784709382612.jpg

Origin Energy confirms cyber breach affecting millions of Australian customers

Origin Energy has confirmed it is investigating a cybersecurity incident in which hackers may have gained unauthorized access to customer data, potentially affecting millions of Australians.

The energy giant disclosed to the Australian Securities Exchange on Wednesday afternoon that it is aware of an incident involving possible unauthorized access to customer information. The company stated it does not believe the compromised data includes customer credit card or bank account details.

With 4.8 million customer accounts across Australia, Origin provides electricity, natural gas, LPG and internet services to residential and business customers. Depending on the breach's severity, the incident could rank among Australia's most significant cyberattacks.

Scale of the breach

The investigation began when The Australian newspaper received an email from an apparent hacker on Tuesday claiming Origin had ignored their communications for nearly three weeks. As evidence, the sender included a sample of 50 customer records containing names, email addresses, phone numbers, residential addresses, billing history and dates of birth.

The suspected hacker, who used a standard Gmail account, stated they had contacted board members, security teams and customer care departments on July 2 but received no substantive response. Origin reportedly asked for proof of the breach but did not receive the evidence at that time.

The hacker wrote in a polite tone that they reached out to the media because Origin had failed to resolve the matter privately. No ransom demand has been made.

Context of Australian cyber threats

The incident occurs against a backdrop of escalating cyber threats across Australia. The Office of the Australian Information Commissioner recorded 1,205 data breach notifications in 2025, an 8 percent increase over 2024 and the highest figure since mandatory reporting began in 2018. Of these breaches, 716 were attributed to malicious or criminal activity, with cyber hacking remaining the primary cause.

Australian Privacy Commissioner Carly Kind has warned that the threat posed to businesses and organizations by data breaches is substantial and rising year on year.

Origin's breach follows major incidents at Optus and Medibank in 2022. The Optus breach affected approximately 9.5 million to 10 million customers, representing roughly one-third of Australia's population, after an exposed, unauthenticated API endpoint remained accessible for up to three months. The Medibank cyberattack compromised data of 9.7 million customers and was described by then-Home Affairs Minister Clare O'Neil as the single most devastating cyberattack Australia had experienced as a nation.

Those breaches prompted the Australian government to introduce cybersecurity legislative reforms, including increasing the maximum penalty for a data breach to 50 million dollars and passing a Cyber Security Act.

Company response

Origin Energy acknowledged the uncertainty such incidents create for customers and stated investigations are proceeding urgently. The company has notified the Australian Federal Police, the Australian Cyber Security Centre and the Office of the Australian Information Commissioner.

Origin has engaged forensic experts to assist with the investigation and indicated it will provide further updates as appropriate. The company expects to share an update on Thursday morning.

Trading in Origin shares fell nearly three percent from the opening price following the announcement.

The breach comes just days after Origin was required by the Australian Competition and Consumer Commission to refund over 270,000 dollars to more than 4,500 customers following an investigation into allegedly misleading representations about the company's Ongoing Saver electricity plan.

According to the Australian Institute of Criminology, nearly half of all Australians experienced at least one form of cybercrime in the 12 months prior to a 2024 survey, underscoring the pervasive nature of digital security threats facing both individuals and organizations.

United KingdomFinancial Conduct AuthorityInsurance ClaimsConsumer RightsIdentity Theft

Share

Twitter/XFacebookLinkedIn

Read also