Origin Energy confirmed on July 23, 2026, that there had been unauthorized access and disclosure of some customers’ data, including names, birth dates, and partial payment details. CEO Frank Calabria apologized in the same ASX statement as government agencies moved to assist.
Quick Summary – TLDR:
- Origin Energy confirmed unauthorized access to and disclosure of some customers’ data in a statement to the ASX on the afternoon of July 23, 2026.
- The exposed data may include names, addresses, phone numbers, dates of birth, account details, and partial credit card or bank account digits.
- The Australian Federal Police, the Australian Cyber Security Centre, and the Office of the Australian Information Commissioner are assisting Origin with its response, per Cyber Daily.
- The Australian newspaper reported an alleged hacker demanded resolution over stolen data tied to up to 4.8 million customers, per Business News Australia.
- The same report says the hacker used the logon of a fired former Origin employee to access the company’s customer management system, per Business News Australia.
What Happened?
Origin can confirm there has been unauthorised access and disclosure of some customers’ data, the company said in the statement to the ASX, Australia’s national stock exchange operator. The retailer added it was working to understand the total number of impacted customers and would contact anyone confirmed to be affected.
The data involved, Origin said, “may include” names and addresses, phone numbers, dates of birth, account details, and either the last four digits of a credit card or the last three digits of a bank account. That mix of identity and partial-payment fields is a familiar target profile in Cybersecurity Statistics data that SQMagazine tracks.
Frank Calabria, Origin Energy’s CEO, apologized directly to customers.
The company said it had set up a dedicated contact number and additional resources, and was working with independent experts alongside authorities. Disclosure emails went out to customers at approximately 3:40am, roughly a day and a half before the ASX statement.
The alleged hacker behind the Origin Energy data breach now claims the personal information of two million customers will not be leaked after a private settlement with the company.
— 10 News (@10NewsAU) July 24, 2026
The hacker also claims they accessed the system using an employee’s login, alleging that staff… pic.twitter.com/ZPlZEiLeC6
The Hacker’s Settlement Claim
A day after Origin’s ASX statement, The Australian newspaper reported it had been in contact with an alleged hacker using the name Edison Walthour, per Business News Australia’s account of the story. The hacker said the stolen data, covering up to 4.8 million customers, would not be released because the matter had been settled privately with Origin.
The Australian’s timeline, as relayed by Business News Australia, says the newspaper first raised the issue with Origin days earlier, after the hacker claimed a threat had been ignored for almost three weeks, and that Origin made the incident public only after the newspaper approached the company for comment. The newspaper further reported the hacker identified as Australian rather than a foreign actor.
Origin has not confirmed any of this. Approached directly by Business News Australia, Origin declined to comment on the settlement report and instead pointed back to its original ASX statement. That gap between the confirmed disclosure and the unconfirmed settlement is the open question in this story.
Implications for Breach Response
Robert Potter, founding partner of the Cyber Activities Group and CEO of Internet 2.0, said
Attackers contact journalists to increase pressure on the victims, establish credibility, accelerate disclosure and turn a private negotiation into a public crisis. Potter said the tactic is designed to force a payment.
That framing matters here because two separate tracks ran in parallel: Origin’s own regulator facing disclosure process, and a private negotiation the company only acknowledged once a newspaper started asking questions. The reported access method used a fired former employee’s still-working login into the customer management system, a distinct failure mode from an external intrusion.
A company can patch every external vulnerability and still be exposed if a departed employee’s credentials stay live.
SQ Magazine’s Takeaway
This reads as two overlapping incidents rather than one. The confirmed part is narrow and specific: Origin has acknowledged unauthorized access to some customers’ identity and partial payment data, apologized, and is still counting how many people are affected. The unconfirmed part is where the real leverage sat.
A hacker able to threaten release of data tied to millions of accounts, and reportedly willing to negotiate privately once media attention arrived, is a company being managed on the extortionist’s schedule rather than its own. Origin declining to comment on the settlement report, while standing by its original disclosure, is a defensible legal posture. It still leaves customers without a clear answer on whether their data was part of any deal.
What’s next: customers should watch for Origin’s direct contact confirming whether their specific data was affected, since the company says it is still finalizing that count. Anyone who received the early morning disclosure email should treat the listed partial card and account digits as a signal to monitor statements, not proof of a full compromise, since Origin noted the fragments alone cannot complete a purchase.
The credential-access question is also unresolved. If a fired employee’s login stayed active, other Origin systems tied to that account deserve a fresh audit, and the Australian Cyber Security Centre’s involvement suggests that review is already underway alongside the company’s own response.