The Origin Energy data breach is a customer-data incident confirmed by the Australian energy and internet provider in July 2026. The company said names, addresses, dates of birth, phone numbers, and Origin account information may have been accessed, together with partial bank-account or payment-card information for some customers.
Origin Energy has 4.8 million customer accounts in Australia, but this does not mean that every account was affected. At the source review date, the company had not yet established which customers or how many people were impacted. LeakData therefore does not use the unverified claim of “two million customers” and records the affected-account count as unknown.
Verified Data Types and Limits
The scope confirmed through the company statement includes names, physical addresses, dates of birth, phone numbers, customer-account information, the last four digits of payment cards, and the last three digits of bank accounts. These partial financial details are not complete card or bank-account numbers. Origin said the fragments could not by themselves be used to make purchases or access bank accounts.
The confirmed notice does not say that passwords, plain-text payment details, complete card numbers, complete bank-account numbers, or security codes were present. However, combining a name, birth date, address, phone number, and customer context can enable targeted fraud. It should also not be assumed that every field was affected for every customer.
Why the Affected Count Is Unknown
Origin Energy said it was working with independent specialists and authorities to determine which datasets were accessed and which customers required notification. The two-million-person figure reported in the media came from an unverified claim by someone purporting to be the attacker. Because no company or regulator has verified it, the number is not included in LeakData statistics.
The organization's total customer-account count cannot be used as the breach scope either. The 4.8 million figure describes Origin's overall customer base, not the number of exposed records. This record can be revised if the company or an authority later publishes a verified count. There is currently no customer dataset imported into LeakData for matching.
Energy-Bill Fraud Scenarios
An attacker who knows a real name, address, phone number, and Origin account context can create convincing messages about overdue bills, direct debit, meter replacement, disconnection, discounts, or refunds. Accurate customer detail in a message does not prove that the sender works for Origin Energy. Independently verify any communication demanding urgent payment or account confirmation.
Type Origin Energy's official address into the browser yourself or call a verified number printed on a bill rather than using the link or number in a message. Do not engage with anyone requesting gift cards, cryptocurrency, remote-access software, or a one-time code. A threat of immediate disconnection combined with an unusual payment method is a strong fraud warning.
Steps for Partial Bank and Card Data
The last four card digits or last three bank-account digits are insufficient to make a payment on their own, but they can be used to build trust during a fraudulent bank or energy-provider call. Even when a caller knows these digits, never disclose the full card details, online-banking password, verification code, or security-question answer.
Enable transaction alerts on bank and card accounts, and review unfamiliar small test charges and newly added payees. If suspicious activity appears, contact the institution directly using the official number printed on the card or published by the bank. Before cancelling a card solely because of this incident, consider the bank's risk assessment and any official notice sent to you by Origin.
Account and Identity-Security Actions
Set a strong Origin password that is not used on any other service, and enable multi-factor authentication if available. Review recovery addresses, connected applications, active sessions, and forwarding rules on the primary email account. If an unfamiliar password-reset or account-change alert appears, close active sessions and change the password from a clean device.
Identity details such as birth date and address may help criminals guess security-question answers on other services. Using unique, non-factual answers stored in a password manager reduces this risk. If you discover an unfamiliar utility, credit, or telecommunications account in your name, contact the organization and the relevant identity-fraud reporting service in your jurisdiction.
How to Interpret the LeakData Record
This record represents a company-confirmed breach, but there are currently no customer rows imported into LeakData and no verified affected-account count. The absence of an Origin Energy result in an email search therefore does not prove that a person was unaffected. Customers who receive a direct notice after the company completes its review should follow the official instructions.
Verify messages claiming to represent Origin Energy through an official channel, enable bank and card alerts, and review account-security settings. If the company contacts you, check the sender domain and navigate to the official site directly. The record includes source notes so it can be updated when a verified count or additional data class is published.