Origin Energy Breach: What Every Business Should Do

Australia's largest electricity and gas retailer is investigating a major data breach, and the data taken is unusually rich - names, addresses, dates of birth, phone numbers and partial card and bank details. The first wave is the headline. The second wave is the scam calls that use the stolen details to sound legitimate, and that wave lands on your staff. Here is what is confirmed and what to do about it.

Security · Data Breach · Australian Business

The Origin Energy Breach and Why Security Is Everyone’s Problem What Was Taken, What Comes Next, and What to Do Now

Australia’s largest electricity and gas retailer is investigating a major data breach. The stolen data is unusually rich — and the second wave, the one that reaches your staff and customers by phone, has not arrived yet.

📅 ⏱ 14 min read 🇦🇺 Australian owned, Australian hosted, Australian supported
TL;DR

In late July 2026, Origin Energy confirmed that customer data had been accessed in a breach now being examined by Australian authorities. Origin said the information may include name, address, date of birth, contact phone number and account information, plus the last four digits of a credit card or the last three digits of a bank account. Origin has around 4.8 million customers and has not confirmed how many people were affected; the individual claiming responsibility told a newspaper he had accessed around two million records, and reporting has since put the confirmed figure closer to 900,000. Investigations involve the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police and the Office of the Australian Information Commissioner. The partial payment details are what make this breach different — they let a scammer open a call with a fact only your bank should know. Combined with generative AI, which can profile two million records in minutes and write flawless, personalised approaches at scale, the follow-on fraud is the real risk. This article covers what is confirmed, what criminals do next, the regulatory picture, and a practical checklist for protecting your business, your staff and your customers — with particular attention to the telephone, which is where the most convincing attacks land.

What Actually Happened

In late July 2026, Origin Energy — Australia’s largest electricity and gas retailer — confirmed that customer data had been accessed and taken in a cyber incident. The breach came to public attention after the person claiming responsibility contacted The Australian, saying he had obtained the records of around two million customers, and provided sample data and screenshots said to be from internal systems.

Origin confirmed that the information involved “may include name, address, date of birth, contact phone number and account information, as well as the last four digits of a credit card, or the last three digits of a bank account”.

What we knowDetail
When Flagged as a potential issue in early July 2026, treated as a credible incident from around 22 July, publicly confirmed and customers notified from 28 July.
Scale Origin has approximately 4.8 million customers and has not itself confirmed how many were affected. The claimant said around two million records; subsequent reporting has put the confirmed number closer to 900,000 current and former customers.
Data types Name, address, date of birth, contact phone number, account information, last four digits of a credit card or last three digits of a bank account.
Nature of the attack Data theft rather than destruction or disruption. No evidence reported of systems being encrypted or services interrupted.
Who is investigating The Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police and the Office of the Australian Information Commissioner.
Unusual feature The claimant contacted media directly and later reportedly agreed not to leak the data after some arrangement with Origin — something Origin has not confirmed. The identity and affiliation of the person remain unverified.
Treat “the data will not be leaked” as irrelevant to your planning

Even where a claimant says data will not be published, nobody can verify that a copy does not exist, has not been shared, or will not surface in eighteen months. Data that has left an organisation should be assumed to be in circulation permanently. Plan for the fraud attempts, not for the reassurance.

Why This Breach Is Different

Australia has had a difficult few years — Optus, Medibank, Qantas and others have all put large volumes of personal information into criminal hands. Australians are, understandably, becoming numb to the announcements. This one deserves attention for a specific reason.

The partial payment details. The last four digits of a card, or the last three of a bank account, are not enough to make a payment. But they are exactly enough to make a scam call believable, because they are precisely the detail a legitimate organisation uses to prove it is legitimate.

“I’m calling from your bank’s fraud team about the card ending 4417.” Everything a customer has been taught about identifying real callers is built on the idea that only the real organisation knows that number. When a criminal has it, the standard verification ritual becomes the attack.

Add a name, a home address and a date of birth, and the caller can pass most casual identity checks in either direction. The person on the other end has no realistic way to distinguish that call from a genuine one — which is why “be vigilant” is such weak advice on its own, and why process, not alertness, has to carry the weight.

What AI Changed About the Economics of Fraud

Before generative AI, a criminal holding two million records faced a labour problem. Reading the data, segmenting it and writing convincing individual approaches took time, and the economics pushed attackers towards generic, misspelt, mass-mailed rubbish that most people could spot.

That constraint is gone. A model can scan a dataset in minutes, cluster by postcode to find affluent suburbs, cross-reference names against public social media, and generate fluent, individually tailored messages at unlimited scale. The tell-tale signs Australians were trained to look for — bad grammar, odd phrasing, generic greetings — have largely stopped being reliable.

🎯

Targeting at scale

Two million records sorted into segments in minutes: high-value postcodes, older customers, business accounts. Each gets a different, appropriate approach.

✍️

Perfect prose, every time

Fluent, correctly formatted, in the register a utility actually uses. The grammar heuristic that protected people for twenty years is dead.

📄

Fabricated documents

Convincing fake bills, statements and payslips. Australian banks have reported a flood of fraudulent home loan applications using AI-generated supporting documents.

🗣️

Cloned voices

A few seconds of audio is enough to imitate someone convincingly on a phone call — covered in depth in AI voice cloning and vishing.

The practical consequence for a business is that staff training built on “spot the dodgy email” no longer works, because there is nothing dodgy to spot. What still works is procedure: verification that does not depend on the attacker’s performance being imperfect.

The Second Wave: Calls, Texts and Fake Invoices

The breach is the event. The fraud is the consequence, and it typically arrives weeks to months later, once the data has been organised and traded.

ApproachWhat it looks likeWhat it is after
The bank fraud call “We’ve stopped a suspicious transaction on the card ending 4417. I need to verify some details.” One-time codes, online banking credentials, or a “transfer to a safe account”.
The energy account text An SMS about an overdue bill or a refund owed, with a link to a convincing payment page. Card details entered voluntarily, or credentials reused elsewhere.
The supplier invoice change An email or call to your accounts team saying a supplier’s bank details have changed. A single large payment redirected. The most costly attack on Australian small business, consistently.
The executive impersonation A call or voice message that sounds like a director, urgently requesting a payment or a gift-card purchase. Immediate transfer, exploiting hierarchy and urgency together.
The IT help desk call “We’re resetting MFA across the business, I’ll need the code that just arrived.” Account takeover, then everything downstream of it.
The slow build Several harmless-seeming contacts over weeks, establishing familiarity before any request. The high-value target that a single cold call would never land.

Harden the Channel Where the Attacks Actually Land

Verified sender IDs, call recording, AI screening of unknown callers, and a phone platform built and hosted in Australia with an Australian team behind it. Talk to us about making your phone system part of your security posture rather than the hole in it.

Talk to Us Or call directly: 1300 881 662

Why This Is Your Problem Even If You Are Not an Origin Customer

It is tempting to file a breach at a big energy retailer under “news” rather than “risk register”. Four reasons not to.

👥

Your staff are in the data

Nearly five million Australian households buy energy from Origin. Statistically, several of your people are in that dataset with their home address, date of birth and mobile number.

🧱

Breaches compound

Criminals merge datasets. Origin plus Optus plus Medibank plus a decade of smaller leaks builds a profile far richer than any single breach, and it never expires.

🏢

Your business is impersonable

Whatever you sell, somebody can ring your customers pretending to be you. Your brand is an asset criminals can borrow, and your customers will blame you either way.

🔑

Home details unlock work accounts

Date of birth and address are still used for identity verification at far too many help desks — including, sometimes, your own.

The Regulatory Picture in 2026

Australia’s framework has tightened considerably, and business obligations have moved with it.

RegimeWhat it means for you
Notifiable Data Breaches scheme If you are covered by the Privacy Act and suffer an eligible data breach likely to cause serious harm, you must notify affected individuals and the OAIC. Assess quickly — the clock and the expectation of promptness are both real.
Privacy Act reform Penalties for serious or repeated interference with privacy have risen substantially, and a statutory tort for serious invasions of privacy now exists. The downside of a breach is no longer mainly reputational.
Scams Prevention Framework Legislated in February 2025, creating obligations on banks, telcos and digital platforms to prevent, detect, disrupt and report scams, with sector codes following. Covered in what the framework means for business.
SMS Sender ID Register Registering your business sender ID stops criminals sending messages that appear in the same thread as your genuine ones — one of the highest-value hours of security work available to a small business. See the Sender ID Register guide.
Sector-specific duties Health, disability, financial services and government suppliers carry additional obligations on top of the general framework. Know which apply to you before you need to.

The Phone Is the Weakest Link and the Best Defence

Email security has had twenty years of investment. Most organisations now filter, sandbox and flag external mail automatically. The telephone has had almost none of that, which is precisely why sophisticated attackers have moved to it.

A phone call carries urgency, social pressure and a human voice, and it leaves no artefact for a security team to inspect afterwards — unless you build one.

ControlWhat it does
Call recording on finance and service lines Creates the artefact. When a payment is questioned three weeks later, the conversation exists rather than being two people’s recollections.
AI screening of unknown callers An AI agent answers unrecognised numbers, establishes who is calling and why, and passes a summary to the human — who is then not answering cold.
Registered sender IDs for SMS Prevents a scammer’s message threading into your legitimate conversation with a customer, which is what makes those texts so convincing.
Published numbers people can call back on Make it easy and normal for a customer to hang up and ring your published number. Say it in your greeting and on your invoices.
Distinct numbers for distinct functions Accounts, support and sales on separate published lines makes anomalies visible and gives customers a stable, verifiable point of contact.
Australian-hosted platform and support Call recordings and metadata are sensitive. Knowing which jurisdiction holds them, and reaching a support team locally during an incident, both matter — see where your calls actually live.
The one rule that defeats almost all of this

Never verify an inbound call using information the caller supplies. If someone rings claiming to be your bank, your supplier or your IT provider, end the call and ring back on a number you already had — from an invoice you hold, from their website, from your own records. Not the number they give you, not the number in the email, not the one that appeared on your screen. Caller ID can be spoofed trivially. This rule costs ninety seconds and defeats the overwhelming majority of voice fraud.

A Practical Security Checklist

Ordered by value for effort. A small business can do the first five in a week.

#ActionWhy it earns its place
1 Multi-factor authentication on email, banking, accounting and your phone system admin. Still the single highest-value control. Prefer an app or hardware key over SMS codes where you can.
2 A written callback rule for any payment or bank-detail change, with no exceptions for urgency or seniority. Directly defeats invoice fraud and executive impersonation, which are where the large losses are.
3 Register your SMS sender ID. An hour of work that removes a whole attack class against your customers.
4 Unique passwords in a password manager, everywhere. Breached credentials get replayed across every service you use. Reuse is what turns one breach into ten.
5 Tell customers how you will and will not contact them, and repeat it. “We will never ring and ask for a code” is worth more on your invoices than any security badge on your website.
6 Minimise what you collect and delete what you no longer need. The cheapest data to protect is the data you never held. Most businesses keep far more, far longer, than they can justify.
7 Recording plus review on finance and service lines. Turns a disputed conversation into a reviewable fact, and gives you real training material.
8 Rehearse the response: who decides, who notifies, who talks to customers. Breach response is a communications exercise under time pressure. Doing it for the first time on the day goes badly.

If You Are the One Who Gets Breached

The Origin incident is a useful case study precisely because the response is being conducted in public.

⏱️

Speed beats polish

A partial, honest update on day one earns more trust than a perfect statement on day nine. The gap gets filled by the attacker’s version otherwise.

📣

Say exactly what was taken

People can only protect themselves if they know which details are out. Vagueness reads as concealment and makes the second wave more effective.

☎️

Expect your phones to melt

Every affected customer rings at once. Overflow, callback queues, an AI agent handling the repeated questions and clear IVR messaging are the difference between managed and overwhelmed.

🚫

Never call customers asking to verify

Post-breach outbound calls requesting identity details train your customers to do exactly what the criminals want. Direct people to ring your published number instead.

That third point is worth planning for concretely. A breach notification going to tens of thousands of customers generates a call volume no ordinary team can absorb. Cloud phone systems can scale queues and add capacity instantly, which is the sort of thing that is easy to arrange in advance and impossible to arrange on the day.

The Cultural Fix That Beats Any Product

Almost every successful scam depends on one thing: a person who suspected something was wrong but did not feel able to slow the interaction down. Fear of seeming rude, of questioning a senior person, of being the one who held up an urgent payment.

Tell your team, in writing and out loud: you will never be criticised for verifying. Not for asking a director to confirm a request through another channel. Not for making a caller wait while you ring back on a published number. Not for refusing an urgent payment until tomorrow. And mean it — the first time somebody is made to feel silly for checking, the policy is gone.

Urgency is the common ingredient in every one of these attacks, because urgency is what stops people verifying. A culture where slowing down is explicitly encouraged removes the mechanism the whole industry depends on, and it costs nothing.

The Origin breach will fade from the news well before its consequences do. The stolen details do not expire, cannot be changed the way a password can, and will be used for years. The businesses that come through it well will not be the ones that read the coverage — they will be the ones that spent a week in August 2026 turning on MFA, writing a callback rule, registering a sender ID and telling their team that checking is always welcome.

Frequently Asked Questions

What happened in the Origin Energy data breach?
In late July 2026 Origin Energy, Australia's largest electricity and gas retailer, confirmed that customer data had been accessed and taken. The incident became public after the person claiming responsibility contacted The Australian newspaper, saying he had obtained records for around two million customers and providing sample data along with screenshots said to be from internal systems. Origin confirmed the information may include name, address, date of birth, contact phone number and account information, as well as the last four digits of a credit card or the last three digits of a bank account. It was flagged internally as a potential issue in early July, treated as credible from around 22 July, and publicly confirmed with customer notifications from 28 July. Origin has approximately 4.8 million customers and has not confirmed how many were affected, though reporting has put the figure closer to 900,000 current and former customers. The Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police and the Office of the Australian Information Commissioner are all involved.
Why is this breach considered more dangerous than earlier ones?
Because of the partial payment details. The last four digits of a credit card, or the last three of a bank account, cannot be used to make a payment - but they are exactly the detail legitimate organisations use to prove to you that they are legitimate. When a criminal opens a call with “I'm from your bank's fraud team about the card ending 4417”, the entire verification ritual that Australians have been taught to rely on becomes the attack itself. Combined with name, home address and date of birth, a caller can pass most casual identity checks, and the person on the other end has no realistic way to tell the call apart from a genuine one. That is why advice to simply be vigilant is so weak here, and why the defence has to be procedural - never verifying an inbound call using information the caller provides, and always ringing back on a number you already held.
How has AI changed the risk from stolen data?
It has removed the labour constraint that used to protect people. Before generative AI, a criminal holding two million records had to spend serious time reading, segmenting and writing individual approaches, so the economics pushed attackers towards generic, misspelt, mass-mailed messages that most recipients could recognise. Now a model can scan the entire dataset in minutes, cluster by postcode to find affluent areas, cross-reference names against public social media, and produce fluent personalised messages at unlimited scale. The heuristics Australians were trained on - bad grammar, odd phrasing, generic greetings - have largely stopped being reliable indicators. AI also generates convincing fake documents, and Australian banks have reported a flood of fraudulent home loan applications supported by AI-generated payslips and statements. Voice cloning adds another dimension, since a few seconds of audio is enough to imitate a specific person on a phone call convincingly.
What should a small business do this week?
Five things, all achievable in a week. Turn on multi-factor authentication for email, banking, accounting and your phone system administration, preferring an authenticator app or hardware key over SMS codes. Write a callback rule stating that any payment or change of bank details is verified by ringing the known number for that supplier, with no exceptions for urgency or seniority - that single rule defeats invoice fraud and executive impersonation, which cause the largest losses for Australian small business. Register your SMS sender ID so criminals cannot slide messages into the same thread as your genuine texts to customers. Move every account to unique passwords in a password manager, because credential reuse is what turns one breach into ten. And tell your customers plainly how you will and will not contact them - a line on your invoice saying you will never ring and ask for a verification code is worth more than any security badge on your website.
What is the one rule that stops most phone-based fraud?
Never verify an inbound call using information that the caller supplies. If somebody rings claiming to be your bank, a supplier, a government agency or your IT provider, end the call and ring back on a number you already had - from an invoice in your files, from your own records, from the organisation's website that you navigated to yourself. Not the number they read out, not the number in the email that prompted the call, and not the number that appeared on your screen, because caller ID is trivially spoofed and should be treated as decoration rather than identification. This costs about ninety seconds and defeats the overwhelming majority of voice fraud, including the bank fraud call, the IT help desk approach and the supplier bank-detail change. The reason it works is that it does not require anyone to detect anything - it does not matter how convincing the caller was, because the verification happens over a channel the attacker does not control.
What are our legal obligations if our own business is breached?
If you are covered by the Privacy Act and suffer an eligible data breach likely to result in serious harm, the Notifiable Data Breaches scheme requires you to notify affected individuals and the Office of the Australian Information Commissioner, and to assess a suspected breach promptly. Privacy Act reform has raised penalties for serious or repeated interference with privacy substantially and introduced a statutory tort for serious invasions of privacy, so the consequences are no longer mainly reputational. Sector-specific duties sit on top for health, disability, financial services and government suppliers. Practically, the response matters as much as the compliance: be fast rather than polished, say specifically what was taken so people can protect themselves, and plan for the call volume, because a notification to thousands of customers generates a phone spike no ordinary team absorbs. And never make outbound calls asking customers to verify their identity afterwards - that trains them to do exactly what the criminals want.
Should we tell customers we will never ask for certain things?
Yes, repeatedly and in the places they will actually see it. A short, specific statement - we will never ring you and ask for a one-time code, we will never ask you to move money to a safe account, our bank details do not change - is one of the most cost-effective security controls available to a business. Put it on invoices, in email footers, on the contact page and in your on-hold message. The reason it works is that it gives your customers a rule they can apply without having to judge how convincing a caller sounds, and judging convincingness is precisely what people are now bad at, given how good AI-assisted approaches have become. Pair it with a published callback number and an explicit invitation to hang up and ring you, said in your own greeting. Making verification feel normal and welcome, rather than rude, is what actually changes behaviour.

What to Read Next

Your next reads

Uniden Voice Over Cloud logo

Australia’s smartest AI-powered cloud phone system — Australian owned, Australian hosted, Australian supported. unidenvoice.com | 1300 881 662