Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for Origin Energy data breach exposing Australian customer data July 2026

Origin Energy Breach Exposes Customer Data: What to Check Now

Origin Energy, Australia's largest energy retailer, confirmed on 23 July that an unauthorised party accessed customer data including names, addresses, dates of birth, phone numbers, and partial payment details. A threat actor claiming responsibility says they hold records for two million of Origin's 4.8 million customers and has threatened to leak the data within two weeks.

Confirmed breach: up to 2 million Origin Energy customer records potentially exposed. If your business or staff have Origin accounts, act now. Credential reuse is the fastest way a consumer breach becomes a corporate one.

Who's Affected

If your business or staff have Origin Energy accounts (electricity, gas, or broadband), assume the associated personal details are compromised until you hear otherwise. Origin is contacting confirmed impacted customers directly. Monitor their incident page for updates.

What to Do Today

  • Check whether anyone in your team uses their Origin account email and password combination on any business systems: email, cloud services, VPNs, or internal tools.
  • If the same password appears anywhere in your business stack, change it now and enable MFA immediately.
  • Brief your team to watch for phishing emails impersonating Origin: fake invoices, "verify your account" messages, or bogus refund offers are the most common follow-up vectors.
  • If you don't have a vendor breach response checklist, start one. Knowing who to notify and what to check when a supplier is breached is a basic operational gap worth closing.
  • Monitor Origin's incident update page for any change in scope or new guidance.

Credential reuse is the single fastest way a consumer breach becomes a corporate one; it's something we see constantly across Australian SMB environments. Attackers routinely weaponise breach data to craft convincing follow-up phishing: with tax-time phishing already at peak levels, this adds another vector your team needs to watch for.

All IT's cybersecurity team can help you build a vendor breach response checklist that's practical to maintain, and assess whether any staff credentials need to be rotated across your business stack. Origin has also notified the Australian Federal Police, the ACSC, and the OAIC.

Related guide: Cybersecurity for Sydney SMBs: our complete guide to protecting your business from cyber threats.

Written by Caleb Attard, Head of Business Operations, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across financial services, hospitality, and not-for-profit sectors from its Brookvale base.


Frequently Asked Questions: Origin Energy Data Breach

Origin Energy confirmed that the exposed data includes customer names, addresses, dates of birth, phone numbers, and partial payment details. A threat actor claims to hold records for approximately two million of Origin's 4.8 million customers. Origin is contacting confirmed impacted customers directly and has notified the Australian Federal Police, the ACSC, and the Office of the Australian Information Commissioner (OAIC).
The most urgent check is credential reuse: whether any staff member uses the same email and password from their Origin account on business systems such as Microsoft 365, cloud platforms, VPNs, or internal tools. If the same password is in use anywhere in your business, it should be changed immediately and MFA enabled. You should also brief staff to expect phishing emails impersonating Origin in the coming weeks.
Attackers use exposed data in two main ways. First, they test known email and password combinations against business systems (credential stuffing). Second, they use personal details from the breach to craft highly convincing phishing emails that impersonate Origin, including fake invoices, account verification requests, and refund offers. These emails are far more convincing than generic phishing because they include real customer details.
If your business holds customer or staff data that could be compromised as a secondary effect of this breach (for example, through credential reuse or a successful phishing attack), you may have notification obligations under the Notifiable Data Breaches scheme. If an attacker gains access to your systems using credentials exposed in the Origin breach, that is a reportable data breach for your organisation. All IT Services can help you assess your exposure and obligations if you're concerned.

Concerned About Credential Exposure in Your Business?

Our team can check whether your staff credentials appear in breach databases, review MFA coverage across your systems, and help you build a vendor breach response process.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →