Origin Energy probes potential unauthorized access to customer data
Origin Energy said a potential incident may have exposed some customers’ data, while reports later pointed to a possible insider theft and 2 million records.

Origin Energy said it was investigating a potential security incident that may involve unauthorized access to some customers’ data, after a hacker claimed access to details for about 2 million customers. The company told the Australian Securities Exchange on 22 July 2026 that it was probing the matter, putting Australia’s largest electricity retailer under immediate scrutiny.
The first concern is the data itself. Origin told authorities it did not believe the affected information included credit card or bank details, and it notified the Australian Cyber Security Centre and the Australian Federal Police. Even without payment data, customer names, contact details and account information can be enough for phishing, identity theft and account takeover attempts, especially when they sit inside a utility’s records that link billing history and service addresses.

Later reporting added a different and narrower possibility: Origin confirmed to Information Age that an employee allegedly attempted to steal sensitive customer data, and Cyber Daily said the company later confirmed a breach after a former staffer allegedly exfiltrated details of more than 700 people. Insurance Business said hundreds of credit card details were involved. If that account holds, the case would shift from a broad external intrusion to an insider threat, a scenario that typically points to failures in access controls, monitoring and offboarding procedures.
The scale matters because Origin sits at the center of essential services. Xinhua described it as Australia’s largest electricity retailer, while other outlets said the hacker’s claim reached roughly 2 million customer records. A company with that kind of footprint can turn even a limited breach into a national issue because the customer base is large, the data is sensitive and the expectations for service reliability are high. Cyber risk has been rising across utilities as well: Reuters reported in September 2024 that cyberattacks on US utilities surged 70% that year.
Origin’s public reporting is likely to face closer attention if the probe confirms a larger exposure. Its 2024 annual report includes a five-year financial history and governance reporting, and its 2024 Sustainability Report says the company’s reporting suite includes governance and sustainability performance data. Investors will be watching for how quickly Origin identifies the affected records, whether any operational systems were touched, and how many customers need to be notified. The size of the fallout will depend on whether the incident was a broad compromise or a contained insider theft, but either way, the company is now under pressure to show that its controls can protect both customers and critical infrastructure.
This article was produced by Prism’s automated news system from verified source data, official records, and press releases, then run through automated quality and moderation checks before publishing. The system is built and supervised by the people who set the standards it runs under. Read our full AI policy.
Did this article answer your question?


