Date: 23 July 2026
Prepared by: Cyber Safe Business (CSB)
Cyber Security Alert
Origin Energy has confirmed that a cybersecurity incident resulted in the unauthorised access and disclosure of customer data. The company stated it is continuing to investigate the incident and determine the total number of affected customers.
According to Origin Energy, information potentially exposed may include:
- Customer names
- Residential addresses
- Dates of birth
- Telephone numbers
- Account information
- The last four digits of credit cards
- The last three digits of bank account numbers
Origin has advised that the partial financial information exposed cannot be used on its own to make purchases or access accounts.
The incident is being investigated with the assistance of the Australian Cyber Security Centre (ACSC), the Australian Federal Police (AFP), and the Office of the Australian Information Commissioner (OAIC).
Why this matters?
While full credit card and bank account details have not been reported as compromised, the exposure of personal information such as names, addresses, dates of birth, phone numbers and account details significantly increases the risk of:
- Targeted phishing emails and SMS messages
- Identity theft and account takeover attempts
- Social engineering scams impersonating Origin Energy
- Credential stuffing attacks against online accounts using exposed personal information
- Business Email Compromise (BEC) attacks that leverage known customer information
Cybercriminals frequently use data from breaches to create highly convincing scam communications designed to trick recipients into revealing passwords, MFA codes, or financial information.
Recommended Actions for Origin Customers
We recommend all Origin Energy customers take the following precautions immediately:
1. Remain Alert for Scams
Be cautious of emails, text messages, or phone calls claiming to be from Origin Energy.
Do not:
- Click links in unexpected emails or SMS messages
- Open unsolicited attachments
- Provide passwords or MFA codes over the phone
- Share personal information without independently verifying the caller
2. Review Online Account Security
If you maintain an online Origin account:
- Change your account password
- Ensure a unique password is used
- Enable multi-factor authentication (MFA) where available
3. Monitor Financial Accounts
Review bank and credit card statements for unusual activity and report suspicious transactions immediately.
4. Be Vigilant for Identity Fraud
Watch for:
- Unexpected account registrations
- Credit enquiries you do not recognise
- Changes to account details you did not request
5. Verify Communications Independently
If contacted regarding the breach, use contact details published on Origin’s official website rather than numbers or links contained in emails or text messages.
Guidance for Businesses
Businesses should assume that threat actors may attempt to use information from this breach to target employees and customers.
We recommend:
Increase Staff Awareness
Alert employees that scam activity related to the breach is likely.
Strengthen Verification Processes
Require independent verification for:
- Payment changes
- New supplier bank details
- Account recovery requests
- Sensitive information requests
Review Security Controls
Ensure:
- Multi-factor authentication is enabled
- Endpoint protection is up to date
- Email filtering and anti-phishing controls are functioning effectively
- Backups are current and regularly tested
Monitor for Suspicious Activity
Look for:
- Unusual login attempts
- Password reset requests
- Increased phishing email activity
- Abnormal outbound communications
CSB Advisory
The Origin incident highlights a growing trend: organisations and individuals are increasingly targeted through the theft of personal information rather than direct financial data.
Even limited personal data can be weaponised by cybercriminals to conduct convincing phishing, credential theft, and business email compromise attacks. Organisations should view incidents like this as a reminder to review their cybersecurity posture and verify that preventive and detective controls remain effective.
A Cybersecurity Adequacy Check can help identify whether current security controls are sufficient to address today’s evolving threat landscape and regulatory expectations.
Sources
- https://www.abc.net.au/news/2026-07-23/origin-energy-confirms-unauthorised-access-customer-data/106948052
- https://www.originenergy.com.au/update-july-2026/
About Cyber Safe Business
Cyber Safe Business helps Barristers, Australian law firms, accounting practices, medical clinics and professional services organisations reduce cyber risk through managed security, compliance support, security awareness training and strategic cybersecurity advisory services.
Is Your Cybersecurity Adequate?
The recent Origin Energy breach demonstrates that organisations of all sizes are potential targets for cybercriminals. A successful attack can lead to the loss of sensitive information, operational disruption, regulatory scrutiny and reputational damage.
Understanding whether your current security controls are adequate to protect your business is no longer optional.
Need a Cybersecurity Adequacy Check?
Cyber Safe Business can help determine whether your organisation’s cybersecurity controls, policies, monitoring capabilities and incident response preparedness are adequate for:
- Your business risks
- Industry obligations and compliance requirements
- Client and stakeholder expectations
- Today’s evolving cyber threat landscape
Our Cybersecurity Adequacy Check provides an independent assessment of your current security posture and identifies practical, prioritised improvements to strengthen your resilience against cyber threats.
Ready to see how cyber-safe your business really is? Complete this below URL link:
https://forms.cybersafebusiness.au/csb/form/CyberAdequacySelfCheck/formperma/fwKD4U-tmRbP6xmZgERT-JVzaYVEBOGAyaynZs9-4Qg
to receive your Cybersecurity Adequacy Score and discover how your current security measures compare against recognised best practices.
Ph. 07 3184 7575 | Web: https://cybersafebusiness.au/contact-us/