SYDNEY, August 21, 2026, 22:18 AEST
- Origin says about 60 customers had full bank account numbers accessed.
- About 900,000 current and former customers were affected overall.
- The company says no stolen customer data has been published.
Origin Energy (ASX:ORG) said full bank account numbers for about 60 customers were accessed during its July data breach. Another 100 customers had an identity-document number accessed. The findings sharpen the risk inside an incident affecting roughly 900,000 people.
The deepest financial exposure was narrowly concentrated. The broader dataset still included names, addresses, birth dates, phone numbers and account details. Some records also contained partial card or bank numbers. That combination can support highly credible impersonation attempts.
| Accessed data category | Approximate customers | Share of 900,000 affected | What Origin confirmed |
|---|---|---|---|
| Mixed personal and account information | 900,000 | 100% | Different combinations by customer |
| Government concession or program numbers | 15,000 | 1.67% | Program-associated numbers |
| Identity-document numbers | 100 | 0.011% | Number only; no scanned document copies |
| Full bank account numbers | 60 | 0.0067% | Full number accessed |
Origin said it has substantially completed a customer-by-customer review. It is sending tailored notices that identify the data involved and the practical steps available. Chief Executive Frank Calabria said the priority was “completing our notifications to them and providing support.”
The company said the alleged attacker has not publicly leaked or disclosed the data. That statement reduces one immediate risk. It does not eliminate private misuse, resale or targeted scams. The criminal investigation remains open.
| Date | Verified development | Status at August 21 |
|---|---|---|
| Early July 2026 | Origin received a potential security threat | Initially assessed as not credible |
| July 22 | New information indicated a security incident | Company began public notifications |
| July 28 | Origin estimated 900,000 people were affected | Initial review completed |
| August 18 | ABC reported a link to a former call-centre worker | Criminal investigation ongoing |
| August 21 | Origin disclosed the most sensitive data counts | Specific notices still being completed |
ABC reported that investigators linked the incident to a former employee at a Manila call centre operated by Accenture (NYSE:ACN). Accenture declined to discuss Origin’s incident while the investigation continues. Origin has not published the technical access path.
The Origin breach is smaller by headcount than three recent Australian incidents. Its latest disclosure is different because it confirms full financial identifiers for a small subset. The comparison below uses each company’s confirmed affected population, not attacker claims.
| Company and incident | Confirmed affected population | Highest-impact verified data in company disclosures | Full financial data confirmed? |
|---|---|---|---|
| Origin Energy (2026) | About 900,000 | Full bank numbers for about 60; ID numbers for about 100 | Yes, for a limited subset |
| Qantas Airways (ASX:QAN), 2025 | 5.7 million unique customers | Names, emails and loyalty data; some addresses, birth dates and phones | No |
| Medibank Private (ASX:MPL), 2022 | About 9.7 million | Personal, contact and health-claims information | No payment-card data reported |
| Optus, owned by Singapore Telecommunications (SGX:Z74), 2022 | 9.8 million customer records | Personal information and identity-document fields | No payment details reported |
Qantas said its compromised system held 5.7 million unique customers. Medibank confirmed about 9.7 million people. Optus reported 9.8 million exposed customer records. The categories and counting methods differ, so scale alone does not measure harm.
Origin is offering specialist identity and cyber support. That includes identity monitoring and 12 months of free credit monitoring. Customers should rely on their individual notice because exposed fields vary. They should independently contact banks through official channels when a message requests action.
The Australian Cyber Security Centre advises people to treat unexpected links, calls and requests cautiously. Multi-factor authentication can protect accounts when passwords are later targeted. It cannot erase identity data already copied.
The breach also reached executive pay. Origin’s board reduced Calabria’s incentive by A$357,000 and cut other executive incentives by A$607,000. The company expects related costs to appear in its 2027 financial year, but has not quantified them.
Risks: Origin has not disclosed the full intrusion method or every security change. Customer counts remain approximate. A continuing criminal investigation could alter attribution, scope or the assessment that no data was publicly released.