Get all your news in one place.
100's of premium titles.
One app.
Start reading
AAP
AAP
Business
Sam McKeith

Bank, credit cards details caught up in Origin breach

Origin Energy has confirmed some customer bank details might have been accessed in a cyberattack. (Joel Carrett/AAP PHOTOS)

A cyberattack on Origin Energy has included unauthorised access and disclosure of customer data, the energy giant says, a day after it revealed it was caught up in the breach.

The Sydney-based company said on Thursday it was working to understand how many of its almost five million customers were affected by the privacy incursion.

Names, addresses, dates of birth, phone numbers and account information could all have been viewed in the breach, Origin said in an ASX statement.

Also at risk were the last four digits of credit cards, or the last three digits of bank accounts.

Origin
Origin is working to determine how many of its customers might be affected by the cyberattack. (Dan Peled/AAP PHOTOS)

Origin chief executive Frank Calabria apologised to customers and said the company was working to contact those affected.

The company has set up a contact number and "additional resources to help manage our response to this incident".

"One of our key priorities is taking action to secure our systems and ensure no further unauthorised access," Mr Calabria said.

"We are working with independent cyber experts to support Origin, and that work is continuing alongside the work of authorities."

The company continued to engage with federal cyber and information agencies on the incident as well as police, according to the statement.

Origin, which has 4.8 million customer accounts in Australia and provides electricity, natural gas, LPG and internet services, said on Wednesday it did not believe the data obtained included credit card or bank details.

An image of hands typing on a keyboard in Sydney
The Origin hack is the biggest high-profile incident since Partnered Health revealed a breach. (Dan Himbrechts/AAP PHOTOS)

Griffith University's Graeme Hughes, an expert on business and consumer issues, said the breach was unlikely to cause cases of payment fraud but marked a "social engineering problem".

"The last four digits for a card, a date of birth, and an authentic billing history are the exact trust signals a businesses uses to verify itself over the phone," Professor Hughes told AAP.

"That makes an unsolicited call about an energy account far more convincing than it should be.

"If comparable Australian breaches have taught us anything, the confirmed scope (of the breach) usually widens rather than narrows."

The breach represents the country's most high-profile cyber incident since Partnered Health, owned by private equity firm Quadrant, said earlier in July that its medical records were breached clinics in Sydney, Melbourne and Canberra.

In 2025, airline Qantas said it had customer data published by cybercriminals, while telco giant Optus and health insurer Medibank were hit in attacks in 2022 that sparked cyber-resilience laws.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.