• 07 3184 7575
  • July 27, 2026
  • 0 Comments

Date: 23 July 2026 
Prepared by: Cyber Safe Business (CSB) 

Cyber Security Alert 

Origin Energy has confirmed that a cybersecurity incident resulted in the unauthorised access and disclosure of customer data. The company stated it is continuing to investigate the incident and determine the total number of affected customers. 

According to Origin Energy, information potentially exposed may include: 

  • Customer names 
  • Residential addresses 
  • Dates of birth 
  • Telephone numbers 
  • Account information 
  • The last four digits of credit cards 
  • The last three digits of bank account numbers 

Origin has advised that the partial financial information exposed cannot be used on its own to make purchases or access accounts. 

The incident is being investigated with the assistance of the Australian Cyber Security Centre (ACSC), the Australian Federal Police (AFP), and the Office of the Australian Information Commissioner (OAIC). 

Why this matters? 

While full credit card and bank account details have not been reported as compromised, the exposure of personal information such as names, addresses, dates of birth, phone numbers and account details significantly increases the risk of: 

  • Targeted phishing emails and SMS messages 
  • Identity theft and account takeover attempts 
  • Social engineering scams impersonating Origin Energy 
  • Credential stuffing attacks against online accounts using exposed personal information 
  • Business Email Compromise (BEC) attacks that leverage known customer information 

Cybercriminals frequently use data from breaches to create highly convincing scam communications designed to trick recipients into revealing passwords, MFA codes, or financial information. 

Recommended Actions for Origin Customers 

We recommend all Origin Energy customers take the following precautions immediately: 

1. Remain Alert for Scams 

Be cautious of emails, text messages, or phone calls claiming to be from Origin Energy. 

Do not: 

  • Click links in unexpected emails or SMS messages 
  • Open unsolicited attachments 
  • Provide passwords or MFA codes over the phone 
  • Share personal information without independently verifying the caller 

2. Review Online Account Security 

If you maintain an online Origin account: 

  • Change your account password 
  • Ensure a unique password is used 
  • Enable multi-factor authentication (MFA) where available 

3. Monitor Financial Accounts 

Review bank and credit card statements for unusual activity and report suspicious transactions immediately. 

4. Be Vigilant for Identity Fraud 

Watch for: 

  • Unexpected account registrations 
  • Credit enquiries you do not recognise 
  • Changes to account details you did not request 

5. Verify Communications Independently 

If contacted regarding the breach, use contact details published on Origin’s official website rather than numbers or links contained in emails or text messages. 

Guidance for Businesses 

Businesses should assume that threat actors may attempt to use information from this breach to target employees and customers. 

We recommend: 

Increase Staff Awareness 

Alert employees that scam activity related to the breach is likely. 

Strengthen Verification Processes 

Require independent verification for: 

  • Payment changes 
  • New supplier bank details 
  • Account recovery requests 
  • Sensitive information requests 

Review Security Controls 

Ensure: 

  • Multi-factor authentication is enabled 
  • Endpoint protection is up to date 
  • Email filtering and anti-phishing controls are functioning effectively 
  • Backups are current and regularly tested 

Monitor for Suspicious Activity 

Look for: 

  • Unusual login attempts 
  • Password reset requests 
  • Increased phishing email activity 
  • Abnormal outbound communications 

CSB Advisory 

The Origin incident highlights a growing trend: organisations and individuals are increasingly targeted through the theft of personal information rather than direct financial data. 

Even limited personal data can be weaponised by cybercriminals to conduct convincing phishing, credential theft, and business email compromise attacks. Organisations should view incidents like this as a reminder to review their cybersecurity posture and verify that preventive and detective controls remain effective. 

A Cybersecurity Adequacy Check can help identify whether current security controls are sufficient to address today’s evolving threat landscape and regulatory expectations. 

Sources 

  • https://www.abc.net.au/news/2026-07-23/origin-energy-confirms-unauthorised-access-customer-data/106948052 
  • https://www.originenergy.com.au/update-july-2026/ 

About Cyber Safe Business 

Cyber Safe Business helps Barristers, Australian law firms, accounting practices, medical clinics and professional services organisations reduce cyber risk through managed security, compliance support, security awareness training and strategic cybersecurity advisory services. 

Is Your Cybersecurity Adequate? 

The recent Origin Energy breach demonstrates that organisations of all sizes are potential targets for cybercriminals. A successful attack can lead to the loss of sensitive information, operational disruption, regulatory scrutiny and reputational damage.  

Understanding whether your current security controls are adequate to protect your business is no longer optional. 

Need a Cybersecurity Adequacy Check? 

Cyber Safe Business can help determine whether your organisation’s cybersecurity controls, policies, monitoring capabilities and incident response preparedness are adequate for: 

  • Your business risks 
  • Industry obligations and compliance requirements 
  • Client and stakeholder expectations 
  • Today’s evolving cyber threat landscape 

Our Cybersecurity Adequacy Check provides an independent assessment of your current security posture and identifies practical, prioritised improvements to strengthen your resilience against cyber threats. 

Ready to see how cyber-safe your business really is? Complete this below URL link:  

https://forms.cybersafebusiness.au/csb/form/CyberAdequacySelfCheck/formperma/fwKD4U-tmRbP6xmZgERT-JVzaYVEBOGAyaynZs9-4Qg 

to receive your Cybersecurity Adequacy Score and discover how your current security measures compare against recognised best practices.  

Ph. 07 3184 7575 | Web: https://cybersafebusiness.au/contact-us/ 

Previous Post
Smartphones Are Now Central to Digital Investigations — and the Pressure Is Growing