Origin Energy, Australia’s largest energy retailer, confirmed on July 28, 2026 that approximately 900,000 current and former customers had personal data accessed in a security incident. The exposed fields include names, residential addresses, dates of birth, phone numbers, and partial payment information.
The disclosure timeline is the part that will follow this company. Origin received a threat in early July and assessed it as not credible. On July 22, new information emerged indicating a breach may in fact have occurred, and Origin notified the ASX. Six days later it confirmed the scale.
Three Weeks Between the Claim and the Confirmation
Extortion claims arrive constantly and most large enterprises receive several a year that turn out to be recycled data, aggregated public records, or outright fabrication. Dismissing one is not automatically negligence — a security team that escalates every unverified claim to the board burns its credibility inside a quarter.
The question that matters is what the initial assessment was based on. There are two very different failures hiding behind “not credible”:
If Origin asked the claimant for proof, received a weak or unverifiable sample, and checked its own logging without finding corroboration, then the process worked and the evidence was genuinely thin. The reversal on July 22 means the attacker eventually produced something better, or telemetry surfaced late.
If the assessment was made without a sample and without a log review — on the basis that the claim looked like the usual noise — then a 900,000-customer breach ran unacknowledged for roughly three weeks while affected people had no reason to watch their accounts.
Origin has not detailed which it was. Australian regulators are likely to ask.
What the Data Enables
The combination disclosed here is a purpose-built identity fraud kit. Name, address, and date of birth together satisfy the knowledge-based verification checks that Australian telcos, banks, and government services still lean on. Add a phone number and the path to a SIM swap opens; add partial payment details and the phishing becomes specific enough to be convincing — an SMS quoting the last four digits of a real card reads as legitimate to almost anyone.
Energy retailers are an unusually rich target for this because they hold verified address history for years, across moves. That is precisely the data used to defeat “which of these addresses have you lived at” verification questions.
Customers should expect Origin-branded phishing referencing real billing details, and should treat any inbound call or message about their account as unverified regardless of what the caller appears to know.
Australia’s Energy and Utility Sector Under Sustained Pressure
Origin joins a long list. Optus (9.8 million) and Medibank (9.7 million) in 2022 rewrote Australian breach law and produced the current penalty regime — up to AU$50 million or 30% of adjusted turnover for serious or repeated privacy interference. Latitude Financial followed in 2023 with 14 million records.
The OAIC’s posture since then has been that scale is not the only aggravating factor. Response conduct — how quickly an organisation determines the facts and how promptly it notifies — carries independent weight under the Notifiable Data Breaches scheme, which requires notification within 30 days of becoming aware of a suspected eligible breach. Origin’s clock arguably started in early July, not July 22, and where the regulator lands on that question is the open issue in this case.
Whether Origin’s 900,000 figure holds is a second open question. Initial victim counts in incidents of this shape have a consistent tendency to move upward as forensics complete, and at least one threat intelligence summary of the week has circulated a substantially higher record count. Origin’s own confirmed number is 900,000 customers; treat anything larger as unverified for now.


