Origin Energy Breach Exposes Customer Data: What to Check Now
Origin Energy, Australia's largest energy retailer, confirmed on 23 July that an unauthorised party accessed customer data including names, addresses, dates of birth, phone numbers, and partial payment details. A threat actor claiming responsibility says they hold records for two million of Origin's 4.8 million customers and has threatened to leak the data within two weeks.
Who's Affected
If your business or staff have Origin Energy accounts (electricity, gas, or broadband), assume the associated personal details are compromised until you hear otherwise. Origin is contacting confirmed impacted customers directly. Monitor their incident page for updates.
What to Do Today
- Check whether anyone in your team uses their Origin account email and password combination on any business systems: email, cloud services, VPNs, or internal tools.
- If the same password appears anywhere in your business stack, change it now and enable MFA immediately.
- Brief your team to watch for phishing emails impersonating Origin: fake invoices, "verify your account" messages, or bogus refund offers are the most common follow-up vectors.
- If you don't have a vendor breach response checklist, start one. Knowing who to notify and what to check when a supplier is breached is a basic operational gap worth closing.
- Monitor Origin's incident update page for any change in scope or new guidance.
Credential reuse is the single fastest way a consumer breach becomes a corporate one; it's something we see constantly across Australian SMB environments. Attackers routinely weaponise breach data to craft convincing follow-up phishing: with tax-time phishing already at peak levels, this adds another vector your team needs to watch for.
All IT's cybersecurity team can help you build a vendor breach response checklist that's practical to maintain, and assess whether any staff credentials need to be rotated across your business stack. Origin has also notified the Australian Federal Police, the ACSC, and the OAIC.
Sources
Written by Caleb Attard, Head of Business Operations, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across financial services, hospitality, and not-for-profit sectors from its Brookvale base.
Frequently Asked Questions: Origin Energy Data Breach
Concerned About Credential Exposure in Your Business?
Our team can check whether your staff credentials appear in breach databases, review MFA coverage across your systems, and help you build a vendor breach response process.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
