Origin Energy says personal data for about 900,000 current and former customers was accessed in a cybersecurity incident. CEO Frank Calabria apologised and the company has started contacting affected customers while extending support and running a forensic review with external specialists. Origin is coordinating with law enforcement and regulators; the incident remains subject to an active criminal investigation. Customers are urged to watch for phishing, avoid unsolicited links and enable two-factor authentication.
Origin Energy Confirms Cyberattack Exposed Personal Data of About 900,000 Customers

Origin Energy says an initial review of a cybersecurity incident found that personal information for roughly 900,000 current and former customers was accessed, making this one of the largest recent breaches to affect an Australian energy retailer.
Immediate Response
Chief Executive Frank Calabria apologised to affected customers and said the company's immediate priority is supporting those impacted. Origin has begun contacting customers whose information was accessed, extended customer support hours, and established dedicated assistance channels while its forensic investigation continues.
Investigation And Coordination
Origin said it is working with external cybersecurity and forensic specialists to contain the incident and has taken additional steps to secure its systems. The company is coordinating with the Australian Cyber Security Centre (ACSC), the National Office of Cyber Security and the Australian Federal Police, and has notified the Office of the Australian Information Commissioner (OAIC).
Timeline
Origin had been investigating a potential security threat since early July but initially judged, based on the information then available, that the threat was not credible. On July 22, new information indicated a security incident may have occurred, prompting Origin to notify the market and affected customers as a precaution.
Criminal Investigation Limits Detail
Origin said the matter remains the subject of an active criminal investigation, which limits the amount of detail it can disclose publicly while law enforcement inquiries continue.
Advice For Customers
The retailer urged all customers — not only those directly contacted — to remain vigilant for phishing attempts and other scams. Customers were advised to avoid clicking unsolicited links, verify communications through official channels, refrain from sharing passwords or financial information, and enable two-factor authentication where available.
Wider Context
The breach comes amid heightened scrutiny of cybersecurity across Australian organisations after a string of high-profile attacks. Regulators have tightened oversight and raised expectations around incident disclosure and customer protections.
Source: Charles Kennedy for Oilprice.com
Help us improve.


































