[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fiqaWl0sgmCPKBLU2KRqlmunqAjN7Pe6IDbE3K5d_ero":3},{"article":4,"iocs":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"e7220024-f174-40e2-9ec7-d0c4d9b4fbb0","Australian energy provider Origin says data breach exposes client data","australian-energy-provider-origin-says-data-breach-exposes-client-data-b80be0","Origin Energy has confirmed that an unauthorized party accessed and subsequently leaked customer data online, exposing sensitive personally identifiable information (PII), among others. [...]","Australian energy provider Origin Energy has confirmed a data breach where an unknown threat actor accessed and leaked customer data online. The exposed information includes full names, physical addresses, dates of birth, phone numbers, account information, and partial credit card and bank account details. The company is notifying affected customers and has engaged with Australian law enforcement and cybersecurity agencies.","Origin Energy confirms data breach exposing customer PII and financial details.","Australian energy provider Origin says data breach exposes client data By Bill Toulas July 23, 2026 04:14 PM 0 Australian energy provider Origin Energy has confirmed a data breach by an unknown threat actor that exposed customers' personally identifiable information (PII). The company has 4.8 million customers and is currently investigating how many of them have been impacted to inform them of the risk via individual notifications. Origin Energy is Australia’s largest energy retailer, providing electricity, natural gas, and broadband internet services to millions of clients across the country. The company is listed on the ASX, has annual revenue of $8.5 billion, and holds a 20% ownership stake in the UK’s renewable energy retailer Octopus. Yesterday, Origin announced that it had launched an investigation into “a potential security incident that may involve unauthorized access to some customers’ data.” An update published today confirms a data breach, listing the following data types as potentially exposed: Full name Physical address Date of birth Phone number Account information Last four digits of credit card Last three digits of bank account The company noted that the exposed financial details are “incomplete” and cannot be used to hijack accounts or make unauthorized charges to clients’ bank accounts. Origin CEO, Frank Calabria, apologized to customers for the sensitive data being exposed, and assured them that the company is taking steps to block further unauthorized access. Also, confirmed impacted clients are being contacted directly and offered support via a dedicated portal and related resources. Origin has informed the Australian Federal Police (AFP), the Australian Cyber Security Centre, and the Office of the Australian Information Commissioner about the incident, and continues to engage with the agencies as needed. Hackers claim large-scale data theft Local media outlet 7news reported that before Origin Energy released its second statement, a threat actor identifying as “John Doe” contacted them to claim the breach. The threat actor alleged to be holding the data types for 2 million Origin customers. Threat actor's message to OriginSource: 7news The hacker claimed that they contacted security teams, customer support, and even board executives, without receiving a response. The hacker has set up a site where he threatens to leak the stolen data in two weeks unless Origin contacts them via Signal to negotiate a solution. Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper Related Articles: Mount Royal University confirms breach as hackers claim attackNAIC says public data stolen in ShinyHunters' PeopleSoft breach7-Eleven confirms data breach claimed by the ShinyHunters gangUpbound says hack caused $13 million in fraudulent Acima leasesSwiss rail giant Stadler rejects $12.3M ransom demand after cyberattack","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Faustralian-energy-provider-origin-says-data-breach-exposes-client-data\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F07\u002F23\u002Forigin.jpg","2026-07-23T20:14:35+00:00","2026-07-23T22:00:16.319806+00:00",8,[18,21,24],{"name":19,"type":20},"Origin Energy","vendor",{"name":22,"type":23},"John Doe","threat_actor",{"name":25,"type":26},"Signal","product","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":27,"icon":29,"name":30,"slug":31},null,"Breaches","breaches",[33,35,40],{"category":34},{"id":27,"icon":29,"name":30,"slug":31},{"category":36},{"id":37,"icon":29,"name":38,"slug":39},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":41},{"id":42,"icon":29,"name":43,"slug":44},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[46],{"type":47,"value":48,"context":49},"domain","signal.org","Threat actor threatened to leak data unless Origin contacts them via Signal."]