Origin Energy has confirmed that approximately 900,000 current and former customers have been affected by a significant cyber security incident, making it one of Australia's largest corporate data breaches in recent years.

The company revealed that an unauthorised third party accessed customer information during a cyberattack that occurred on 22 July 2026. Following the discovery of the incident, Origin immediately launched an internal investigation and notified relevant government agencies and affected customers.

According to Origin, the information that may have been accessed includes customer names, residential addresses, dates of birth, phone numbers and account details. In some cases, the final four digits of customers' credit cards and the last three digits of linked bank account numbers were also exposed.

Importantly, Origin said that complete payment card numbers, banking passwords and online account passwords were not compromised during the incident.

Chief Executive Frank Calabria said the company had previously investigated a potential security threat earlier in July but initially determined that the information received was not credible. However, new intelligence received on 22 July confirmed that a cyber security incident had likely occurred, prompting an immediate response.

Origin apologised to affected customers, acknowledging the concern and inconvenience caused by the breach.

The company is now working closely with the Australian Cyber Security Centre (ACSC), law enforcement agencies and other government authorities to investigate how the attack occurred and identify those responsible.

As the investigation continues, Origin has urged customers to remain vigilant against possible scams. Criminals may attempt to use the stolen information to impersonate Origin staff through phone calls, emails or text messages in an attempt to obtain additional personal or financial information.

Customers have been advised to carefully verify any unexpected communication claiming to come from Origin. The company stressed that customers should never provide passwords, banking PINs, verification codes or other sensitive information unless they are certain they are communicating with an official representative.

Cyber security experts warn that even when financial information is not fully exposed, personal identification details such as names, addresses and dates of birth can be valuable to cybercriminals attempting identity theft or phishing attacks.

Origin has begun contacting customers whose information may have been affected and is continuing its investigation to determine the full scope of the incident.

With approximately 4.8 million customer accounts across Australia, Origin is one of the country's largest energy providers, supplying electricity, natural gas, LPG and internet services.

The incident follows several other major cyber security events affecting Australian organisations, reinforcing ongoing concerns about digital security and the growing sophistication of cybercriminals targeting large businesses.

Authorities continue to investigate the Origin breach while encouraging Australians to remain alert for suspicious communications, regularly monitor financial accounts and report potential scam activity.

Origin says it will continue providing updates to customers as more information becomes available and additional security measures are implemented.