Origin Energy has confirmed that hackers accessed customers' names, addresses, dates of birth, phone numbers and partial bank account details in a cyber attack. The company, which has 4.8 million customer accounts in Australia, made the announcement in a statement to the Australian Securities Exchange (ASX) on Thursday.
Scope of the breach
Origin has not yet confirmed which or how many customers were affected. A person claiming to be the hacker has reportedly contacted media outlets with unverified claims that 2 million customers' details were accessed. The company said it will inform customers once it confirms whether they were affected.
Data stolen may include customers' names, addresses, dates of birth, phone numbers, Origin account information, and the last four digits of a credit card or the last three digits of a bank account. Origin stated that incomplete credit card or bank account information could not be used to make purchases or access accounts.
Company response
Origin first revealed the hack on Wednesday, initially believing credit card or bank details had not been accessed. The company has not detailed how the hack occurred. Chief executive Frank Calabria said Origin is securing its systems and working with independent cyber experts and authorities to prevent further unauthorized access.
"I'm sorry this has happened," Calabria said. "Customers trust Origin with their information, and I apologise for the impact this may cause."
Expert warnings
Experts have warned that the leaked data could be used for identity theft or by scammers impersonating legitimate businesses. Rumpa Dasgupta, a lecturer in cybersecurity at La Trobe University, said personalized records could also be misused for physical crimes.
"In the wrong hands, this information could be exploited not only for highly targeted phishing campaigns but also to support physical crimes such as burglary by identifying vulnerable properties," Dasgupta said.
Investigations underway
The Australian Cyber Security Centre, the Australian Federal Police (AFP), and the Office of the Australian Information Commissioner (OIAC) are all investigating. The National Office of Cyber Security is leading the government's response. The AFP declined to comment on whether it had identified or communicated with Origin's hackers.
The Australian newspaper reported it was first contacted by a person claiming to have hacked Origin on Tuesday, after which it alerted Origin, leading to Wednesday's statement. An Origin spokesperson said the company moved immediately to update the ASX as soon as it was aware of a potential incident.
Broader context
The OIAC reported receiving 1,205 data breach notifications in 2025, of which 716 were related to malicious or criminal activity. In October, a leak of 5 million Qantas customers' information prompted warnings that scammers could cold call leaked phone numbers. The federal privacy commissioner later found Qantas did not breach the Privacy Act in relation to that hack, and the AFP is investigating.



