{"id":570,"date":"2026-07-27T12:00:51","date_gmt":"2026-07-27T02:00:51","guid":{"rendered":"https:\/\/qld.cybersafebusiness.au\/index.php\/2026\/07\/27\/origin-energy-confirms-customer-data-breach\/"},"modified":"2026-07-27T12:00:51","modified_gmt":"2026-07-27T02:00:51","slug":"origin-energy-confirms-customer-data-breach","status":"publish","type":"post","link":"https:\/\/qld.cybersafebusiness.au\/index.php\/2026\/07\/27\/origin-energy-confirms-customer-data-breach\/","title":{"rendered":"Origin Energy Confirms Customer Data Breach"},"content":{"rendered":"<p><b>Date:\u00a023\u00a0July 2026\u00a0<br \/>Prepared by:\u00a0Cyber Safe Business (CSB)\u00a0<\/b><\/p>\n<\/p>\n<p><b>Cyber Security Alert\u00a0<\/b><\/p>\n<p>Origin Energy has confirmed that a cybersecurity incident resulted in the\u00a0unauthorised access and disclosure of customer data. The company\u00a0stated\u00a0it is continuing to investigate the incident and\u00a0determine\u00a0the total number of affected customers.\u00a0<\/p>\n<p>According to Origin Energy, information potentially exposed may include:\u00a0<\/p>\n<ul>\n<li>Customer names\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Residential addresses\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Dates of birth\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Telephone numbers\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Account information\u00a0<\/li>\n<\/ul>\n<ul>\n<li>The last four digits of credit cards\u00a0<\/li>\n<\/ul>\n<ul>\n<li>The last three digits of bank account numbers\u00a0<\/li>\n<\/ul>\n<p>Origin has\u00a0advised\u00a0that the partial financial information exposed cannot be used on its own to make purchases or access accounts.\u00a0<\/p>\n<p>The incident is being investigated with the\u00a0assistance\u00a0of the Australian Cyber Security Centre (ACSC), the Australian Federal Police (AFP), and the Office of the Australian Information Commissioner (OAIC).\u00a0<\/p>\n<\/p>\n<p><b>Why this matters?\u00a0<\/b><\/p>\n<p>While full credit card and bank account details have not been reported as compromised, the exposure of personal information such as names, addresses, dates of birth, phone numbers and account details significantly\u00a0increases\u00a0the risk of:\u00a0<\/p>\n<ul>\n<li>Targeted phishing emails and SMS messages\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Identity theft and account takeover attempts\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Social engineering\u00a0scams\u00a0impersonating Origin Energy\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Credential stuffing attacks against online accounts using exposed personal information\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Business Email Compromise (BEC) attacks that\u00a0leverage\u00a0known customer information\u00a0<\/li>\n<\/ul>\n<p>Cybercriminals\u00a0frequently\u00a0use data from breaches to create highly convincing\u00a0scam\u00a0communications designed to trick recipients into revealing passwords, MFA codes, or financial information.\u00a0<\/p>\n<\/p>\n<p><b>Recommended Actions for Origin Customers\u00a0<\/b><\/p>\n<p>We recommend all Origin Energy customers take the following precautions\u00a0immediately:\u00a0<\/p>\n<p><b>1. Remain Alert for Scams\u00a0<\/b><\/p>\n<p>Be cautious of emails, text messages, or phone calls claiming to be from Origin Energy.\u00a0<\/p>\n<p>Do not:\u00a0<\/p>\n<ul>\n<li>Click links in unexpected emails or SMS messages\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Open unsolicited attachments\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Provide passwords or MFA codes over the phone\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Share personal information without independently verifying the caller\u00a0<\/li>\n<\/ul>\n<p><b>2. Review Online Account Security\u00a0<\/b><\/p>\n<p>If you\u00a0maintain\u00a0an online Origin account:\u00a0<\/p>\n<ul>\n<li>Change your account password\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Ensure a unique password is used\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Enable multi-factor authentication (MFA) where available\u00a0<\/li>\n<\/ul>\n<p><b>3. Monitor Financial Accounts\u00a0<\/b><\/p>\n<p>Review bank and credit card statements for unusual activity and report suspicious transactions\u00a0immediately.\u00a0<\/p>\n<p><b>4. Be Vigilant for Identity Fraud\u00a0<\/b><\/p>\n<p>Watch for:\u00a0<\/p>\n<ul>\n<li>Unexpected account registrations\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Credit enquiries you do not recognise\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Changes to account details you did not request\u00a0<\/li>\n<\/ul>\n<p><b>5. Verify Communications Independently\u00a0<\/b><\/p>\n<p>If contacted\u00a0regarding\u00a0the breach, use contact details published on Origin&#8217;s official website rather than numbers or links contained in emails or text messages.\u00a0<\/p>\n<\/p>\n<p><b>Guidance for Businesses\u00a0<\/b><\/p>\n<p>Businesses should assume that threat actors may\u00a0attempt\u00a0to use information from this breach to target employees and customers.\u00a0<\/p>\n<p>We recommend:\u00a0<\/p>\n<p><b>Increase Staff Awareness\u00a0<\/b><\/p>\n<p>Alert employees that\u00a0scam\u00a0activity related to the breach is likely.\u00a0<\/p>\n<p><b>Strengthen Verification Processes\u00a0<\/b><\/p>\n<p>Require independent verification for:\u00a0<\/p>\n<ul>\n<li>Payment changes\u00a0<\/li>\n<\/ul>\n<ul>\n<li>New supplier bank details\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Account recovery requests\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Sensitive information requests\u00a0<\/li>\n<\/ul>\n<p><b>Review Security Controls\u00a0<\/b><\/p>\n<p>Ensure:\u00a0<\/p>\n<ul>\n<li>Multi-factor authentication is enabled\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Endpoint protection is up to date\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Email filtering and anti-phishing controls are functioning effectively\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Backups are current and regularly tested\u00a0<\/li>\n<\/ul>\n<p><b>Monitor for Suspicious Activity\u00a0<\/b><\/p>\n<p>Look for:\u00a0<\/p>\n<ul>\n<li>Unusual login attempts\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Password reset requests\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Increased phishing email activity\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Abnormal outbound communications\u00a0<\/li>\n<\/ul>\n<p><b>CSB Advisory\u00a0<\/b><\/p>\n<p>The Origin incident highlights a growing trend: organisations and individuals are increasingly targeted through the theft of personal information rather than direct financial data.\u00a0<\/p>\n<p>Even limited personal data can be weaponised by cybercriminals to conduct convincing phishing, credential theft, and business email compromise attacks. Organisations should view incidents like this as a reminder to review their cybersecurity posture and verify that preventive and detective controls\u00a0remain\u00a0effective.\u00a0<\/p>\n<p>A\u00a0Cybersecurity Adequacy Check\u00a0can help\u00a0identify\u00a0whether current security controls are sufficient to address today&#8217;s evolving threat landscape and regulatory expectations.\u00a0<\/p>\n<\/p>\n<p><b>Sources\u00a0<\/b><\/p>\n<ul>\n<li>https:\/\/www.abc.net.au\/news\/2026-07-23\/origin-energy-confirms-unauthorised-access-customer-data\/106948052\u00a0<\/li>\n<\/ul>\n<ul>\n<li>https:\/\/www.originenergy.com.au\/update-july-2026\/\u00a0<\/li>\n<\/ul>\n<p><b>About Cyber Safe Business\u00a0<\/b><\/p>\n<p>Cyber Safe Business helps\u00a0Barristers,\u00a0Australian law firms, accounting practices, medical\u00a0clinics\u00a0and professional services organisations reduce cyber risk through managed security, compliance support, security awareness\u00a0training\u00a0and strategic cybersecurity advisory services.\u00a0<\/p>\n<\/p>\n<p><b>Is Your Cybersecurity Adequate?\u00a0<\/b><\/p>\n<p>The recent\u00a0Origin Energy\u00a0breach\u00a0demonstrates\u00a0that organisations of all sizes are potential targets for cybercriminals. A successful attack can lead to the loss of sensitive information, operational disruption, regulatory\u00a0scrutiny\u00a0and reputational damage.\u00a0\u00a0<\/p>\n<p>Understanding whether your current security controls are adequate to protect your business is no longer optional.\u00a0<\/p>\n<p><b>Need a Cybersecurity Adequacy Check?\u00a0<\/b><\/p>\n<p>Cyber Safe Business can help\u00a0determine\u00a0whether your organisation&#8217;s cybersecurity controls, policies,\u00a0monitoring\u00a0capabilities and incident response preparedness are adequate for:\u00a0<\/p>\n<ul>\n<li>Your business risks\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Industry obligations and compliance requirements\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Client and stakeholder expectations\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Today&#8217;s evolving cyber threat landscape\u00a0<\/li>\n<\/ul>\n<p>Our <b>Cybersecurity Adequacy Check<\/b> provides an independent assessment of your current security posture and\u00a0identifies\u00a0practical, prioritised improvements to strengthen your resilience against cyber threats.\u00a0<\/p>\n<p>Ready to see how cyber-safe your business really is?\u00a0Complete this below URL link:\u00a0\u00a0<\/p>\n<p><b>https:\/\/forms.cybersafebusiness.au\/csb\/form\/CyberAdequacySelfCheck\/formperma\/fwKD4U-tmRbP6xmZgERT-JVzaYVEBOGAyaynZs9-4Qg\u00a0<\/b><\/p>\n<p>to receive your Cybersecurity Adequacy Score and discover how your current security measures compare against recognised best practices.\u00a0\u00a0<\/p>\n<p><b>Ph. 07 3184 7575\u00a0| Web:\u00a0https:\/\/cybersafebusiness.au\/contact-us\/\u00a0<\/b><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Date:\u00a023\u00a0July 2026\u00a0Prepared by:\u00a0Cyber Safe Business (CSB)\u00a0 Cyber Security Alert\u00a0 Origin Energy has confirmed that a cybersecurity incident resulted in the\u00a0unauthorised access and disclosure of customer data. The company\u00a0stated\u00a0it is continuing [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":569,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[],"tags":[],"class_list":["post-570","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/posts\/570","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/comments?post=570"}],"version-history":[{"count":0,"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/posts\/570\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/media\/569"}],"wp:attachment":[{"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/media?parent=570"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/categories?post=570"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qld.cybersafebusiness.au\/index.php\/wp-json\/wp\/v2\/tags?post=570"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}