Energy giant Origin Energy has confirmed that around 900,000 current and former customers were affected by a major data breach, following an initial review into a cybersecurity incident that exposed customer information.
The company said the breach involved unauthorised access to customer data, with information such as names, contact details, dates of birth, account information and some partial financial details potentially compromised. Origin has stressed that incomplete payment information was not enough to directly conduct transactions, but warned customers about the increased risk of scams and fraudulent activity.
Origin’s investigation began after the company was alerted to a possible security issue earlier in July. The company initially assessed the threat but later confirmed the incident after further evidence indicated that customer information had been accessed.
Chief executive Frank Calabria apologised to affected customers, saying the company was working with cybersecurity experts and government authorities, including law enforcement and cyber agencies, to investigate the breach and strengthen protections.
The incident has raised fresh concerns about cybersecurity risks facing Australia’s critical infrastructure providers. Energy companies hold large amounts of sensitive customer data, making them attractive targets for cybercriminals seeking personal information that can be used in identity theft and scam campaigns.
Customers affected by the breach have been advised to remain cautious of suspicious emails, phone calls or text messages claiming to be from Origin or related services. The company said it would continue contacting impacted customers as the investigation progresses.
The breach adds to growing pressure on Australian businesses to improve cybersecurity systems, data protection practices and response plans as cyberattacks become increasingly frequent and sophisticated.
