July 28, 2026 — 11:43amAustralia’s largest electricity and gas retailer has confirmed that the personal information of about 900,000 current and former customers was accessed in a major cybersecurity incident.Origin Energy chief executive Frank Calabria issued an apology to customers on Tuesday and said the company had begun contacting affected individuals to offer identity protection and cyber support services.Frank Calabria is the chief executive of Origin Energy.Trevor Collens“At this point in time, we believe the information of approximately 900,000 current and former customers was accessed,” Calabria said.“To our customers, I am sorry. We don’t take for granted the trust customers place in Origin and our safeguarding of their information.”Calabria said he was unable to confirm or deny whether whoever was behind the attack had demanded a ransom – or if Origin had made any such payment – while investigations were ongoing.He was also unable to say whether any current or former Origin employees were being investigated over the incident. “I can’t share any further information about the specific nature of the incident because of the criminal investigation,” he said.Origin, which supplies power, natural gas and telecommunications to 4.7 million customers nationally, first disclosed the threat of a data breach to customers and the market last week. Affected customers’ data may include their name, address, date of birth, contact phone number, account information, the final four digits of their credit card and the final three digits of bank accounts, it said.Calabria on Tuesday confirmed it took Origin nearly three weeks from when it was first alerted to the “potential security threat” via email on July 2, until it ultimately deemed it credible.He said the company had worked to confirm the threat’s credibility, but was initially assessed not to be credible, and it had no information to suggest any customer’s information had been compromised.That assessment changed on July 22, when new information emerged indicating that a security breach may have occurred. Origin said it immediately notified the market and alerted customers as a precaution.“As soon as we became aware of a credible incident, which was Wednesday last week, we acted immediately,” Calabria said.Asked why the breach of Origin’s systems went undetected, he said the company had launched a review of the incident and had taken steps to ensure it did not happen again.Origin’s data breach adds to a growing list of Australian organisations and institutions to have suffered major cybersecurity problems in recent years, including Optus, Qantas and Medibank. Healthcare provider Partnered Health this month had sensitive medical records and personal information stolen from its national network of GP clinics.Origin warned customers to be cautious of unexpected calls, emails or text messages referring to their Origin accounts, and urged them not to click on links in unsolicited messages. It also said they should independently verify anyone claiming to represent the company through official contact channels, and never disclose passwords or sensitive personal or financial information unless they were certain whom they were dealing with.Customers were also encouraged to enable two-step authentication on email and other online accounts wherever possible.“We are acutely aware that others may exploit this incident, including by impersonating Origin or through other scam activity,” Calabria said. “We recommend that all our customers remain vigilant to suspicious activity and a heightened risk of scams.”The Business Briefing newsletter delivers major stories, exclusive coverage and expert opinion. Sign up to get it every weekday morning.Nick Toscano is a business reporter for The Age and Sydney Morning Herald.Connect via X or email.David Swan is the technology editor for The Age and The Sydney Morning Herald. He was previously technology editor for The Australian newspaper.Connect via X or email.From our partners
Origin Energy says 900,000 customers had data hacked
A major cyberattack has compromised personal data belonging to 900,000 current and former customers of Australia’s largest energy retailer.










