Origin Energy Breach Exposed Full Bank Numbers for 60 Customers

Origin Energy Breach Exposed Full Bank Numbers for 60 Customers

August 21, 2026

SYDNEY, August 21, 2026, 22:18 AEST

  • Origin says about 60 customers had full bank account numbers accessed.
  • About 900,000 current and former customers were affected overall.
  • The company says no stolen customer data has been published.

Origin Energy (ASX:ORG) said full bank account numbers for about 60 customers were accessed during its July data breach. Another 100 customers had an identity-document number accessed. The findings sharpen the risk inside an incident affecting roughly 900,000 people.

The deepest financial exposure was narrowly concentrated. The broader dataset still included names, addresses, birth dates, phone numbers and account details. Some records also contained partial card or bank numbers. That combination can support highly credible impersonation attempts.

Accessed data categoryApproximate customersShare of 900,000 affectedWhat Origin confirmed
Mixed personal and account information900,000100%Different combinations by customer
Government concession or program numbers15,0001.67%Program-associated numbers
Identity-document numbers1000.011%Number only; no scanned document copies
Full bank account numbers600.0067%Full number accessed

Origin said it has substantially completed a customer-by-customer review. It is sending tailored notices that identify the data involved and the practical steps available. Chief Executive Frank Calabria said the priority was “completing our notifications to them and providing support.”

The company said the alleged attacker has not publicly leaked or disclosed the data. That statement reduces one immediate risk. It does not eliminate private misuse, resale or targeted scams. The criminal investigation remains open.

DateVerified developmentStatus at August 21
Early July 2026Origin received a potential security threatInitially assessed as not credible
July 22New information indicated a security incidentCompany began public notifications
July 28Origin estimated 900,000 people were affectedInitial review completed
August 18ABC reported a link to a former call-centre workerCriminal investigation ongoing
August 21Origin disclosed the most sensitive data countsSpecific notices still being completed

ABC reported that investigators linked the incident to a former employee at a Manila call centre operated by Accenture (NYSE:ACN). Accenture declined to discuss Origin’s incident while the investigation continues. Origin has not published the technical access path.

The Origin breach is smaller by headcount than three recent Australian incidents. Its latest disclosure is different because it confirms full financial identifiers for a small subset. The comparison below uses each company’s confirmed affected population, not attacker claims.

Company and incidentConfirmed affected populationHighest-impact verified data in company disclosuresFull financial data confirmed?
Origin Energy (2026)About 900,000Full bank numbers for about 60; ID numbers for about 100Yes, for a limited subset
Qantas Airways (ASX:QAN), 20255.7 million unique customersNames, emails and loyalty data; some addresses, birth dates and phonesNo
Medibank Private (ASX:MPL), 2022About 9.7 millionPersonal, contact and health-claims informationNo payment-card data reported
Optus, owned by Singapore Telecommunications (SGX:Z74), 20229.8 million customer recordsPersonal information and identity-document fieldsNo payment details reported

Qantas said its compromised system held 5.7 million unique customers. Medibank confirmed about 9.7 million people. Optus reported 9.8 million exposed customer records. The categories and counting methods differ, so scale alone does not measure harm.

Origin is offering specialist identity and cyber support. That includes identity monitoring and 12 months of free credit monitoring. Customers should rely on their individual notice because exposed fields vary. They should independently contact banks through official channels when a message requests action.

The Australian Cyber Security Centre advises people to treat unexpected links, calls and requests cautiously. Multi-factor authentication can protect accounts when passwords are later targeted. It cannot erase identity data already copied.

The breach also reached executive pay. Origin’s board reduced Calabria’s incentive by A$357,000 and cut other executive incentives by A$607,000. The company expects related costs to appear in its 2027 financial year, but has not quantified them.

Risks: Origin has not disclosed the full intrusion method or every security change. Customer counts remain approximate. A continuing criminal investigation could alter attribution, scope or the assessment that no data was publicly released.

BEZ KABLI • EXTENDED COVERAGE

Further analysis

How many Origin Energy customers were affected?
About 900,000 current and former customers were affected. The data varied by person. It could include names, addresses, birth dates, phone numbers, account information and partial payment details.
Were full bank account numbers accessed?
Yes, for approximately 60 customers. Origin also confirmed about 100 customers had an identity-document number accessed. No scanned identity documents were involved.
Has the stolen customer data been published?
Origin says the alleged attacker has not publicly leaked or disclosed it. The criminal investigation continues. Private misuse or future disclosure therefore cannot be ruled out.
What support is Origin providing?
Origin is offering specialist identity and cyber support. This includes identity monitoring and 12 months of free credit monitoring. Tailored notices should identify each customer's exposed fields.
What should affected customers do now?
Read Origin's individual notice and watch for unusual bank activity. Verify unexpected calls or messages through official contact channels. Use multi-factor authentication where available. Never share passwords or financial details in response to an unsolicited request.

Mateusz Brzeziński

Mateusz Brzeziński is a financial and technology journalist at Bez-kabli.pl, covering stocks, artificial intelligence, semiconductors and global market developments. He graduated from the Prague University of Economics and Business in the Czech Republic and previously worked in financial analysis before moving into business journalism. His reporting focuses on the companies, technologies and market trends shaping the global economy.