Origin Energy
Someone emailed on July 2 claiming to hold their customer records. Origin looked, found no evidence, and moved on. Twenty days later the sender supplied proof.
What happened?
On July 2, 2026, Origin Energy received emails from an individual claiming to have accessed customer records. The company assessed the claim and did not initially consider it credible, because there was no evidence confirming customer data had been accessed. On July 22, the sender provided proof. Origin announced it was investigating a potential security incident on July 23.
On July 28, Origin confirmed that approximately 900,000 current and former customers had data accessed and exfiltrated. Origin is Australia's largest energy retailer. The company notified the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner.
What data was actually inside?
Confirmed exposed: names, addresses, dates of birth, phone numbers, account details, and partial payment information — specifically the last four digits of credit cards, or the BSB and last three digits of bank accounts. Origin has stated it does not believe full credit card or bank account details were included.
The partial payment data deserves attention rather than relief. A BSB identifies the specific branch of a specific Australian bank. Combined with a name, address, date of birth, and the last three digits of the account, it gives a caller enough to pass identity verification at that institution — without ever holding the full account number.
Who gets hurt and how?
900,000 Australian households, including former customers who ended their relationship with Origin years ago and had no reason to think the company still held their details.
Name, address, date of birth, and phone number is the standard identity verification set used by Australian banks, telcos, and government services. The immediate risk is not card fraud — it is social engineering and SIM-swap attempts against people whose verification answers are now known. Energy account data compounds it: a service address confirms current residency, which is precisely what a fraudulent credit application needs. Origin customers should expect targeted phishing that correctly cites their account details, because the attacker has them.
What did they think they were doing right?
Origin did what a mature security function is supposed to do with an unverified extortion email: it investigated rather than panicking. Extortion claims against large consumer brands are constant, and most are bluffs recycled from old datasets. Announcing a breach on the strength of an unsubstantiated email is its own harm.
So the company looked at its systems and found no evidence of unauthorised access. That conclusion was reached in good faith. The problem is what "no evidence" means when you cannot fully enumerate what data existed or who touched it — it collapses into "we could not tell either way," which is a very different finding, and it does not read that way in a briefing.
What did they not know about their own data?
For twenty days, an attacker knew more about Origin's customer data than Origin did. The gap did not close through internal investigation. It closed when the attacker chose to prove it, on the attacker's schedule.
The presence of former customers in the exposed population points at the same underlying issue. 900,000 records including people who left implies retention beyond the active customer base — data held because deleting it was never anybody's project, sitting in systems whose contents had not been enumerated recently enough to check a claim against.
Origin's July 2 assessment was not wrong about the evidence. It was constrained by a data map that could not answer the question being asked.
If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?
What does attribution look like the morning after?
Australia's Notifiable Data Breaches scheme requires an entity to assess a suspected eligible breach within 30 days and notify the OAIC and affected individuals as soon as practicable once serious harm is likely. Origin's timeline runs 26 days from the first email on July 2 to confirmed scope on July 28 — inside the assessment window, but consumed almost entirely by determining whether there was anything to assess.
Because the exposure includes former customers, Origin must notify people who are no longer reachable through active account channels. Contact details on file for someone who left in 2019 are frequently stale, which turns notification into a records exercise before it becomes a mailing exercise. Involvement of the ACSC and AFP is standard for an incident of this scale; the OAIC engagement is where the regulatory consequence, if any, will surface.
What would have changed the outcome?
The ability to test an extortion claim against a current map of what data exists and where — turning "we found no evidence" into a finding rather than a shrug.
The twenty-day gap is the whole lesson. Origin was not slow, negligent, or dismissive; it was unable to disprove a claim about its own records, so the attacker controlled when disclosure happened. Organisations that maintain a live inventory of sensitive data can triage an extortion email in hours and either escalate immediately or dismiss it with evidence. Everyone else waits to be shown. See also our analysis of the RingCentral extortion listing, where the same verification problem played out against a 48-hour deadline.
Origin Energy found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.