Factual. Independent. Impartial.
Support AAP with a free or paid subscription
Finance
Sam McKeith

Bank, credit cards details caught up in Origin breach

Origin Energy has confirmed some customer bank details might have been accessed in a cyberattack. (Joel Carrett/AAP PHOTOS)

A cyberattack on Origin Energy has included unauthorised access and disclosure of customer data, the energy giant says, a day after it revealed it was caught up in the breach.

The Sydney-based company said on Thursday it was working to understand how many of its almost five million customers were affected by the privacy incursion.

Names, addresses, dates of birth, phone numbers and account information could all have been viewed in the breach, Origin said in an ASX statement.

Also at risk were the last four digits of credit cards, or the last three digits of bank accounts.

Origin
Origin is working to determine how many of its customers might be affected by the cyberattack. (Dan Peled/AAP PHOTOS)

Origin chief executive Frank Calabria apologised to customers and said the company was working to contact those affected.

The company has set up a contact number and "additional resources to help manage our response to this incident".

“One of our key priorities is taking action to secure our systems and ensure no further unauthorised access," Mr Calabria said.

"We are working with independent cyber experts to support Origin, and that work is continuing alongside the work of authorities."

The company continued to engage with federal cyber and information agencies on the incident as well as police, according to the statement.

Origin, which has 4.8 million customer accounts in Australia and provides electricity, natural gas, LPG and internet services, said on Wednesday it did not believe the data obtained included credit card or bank details.

An image of hands typing on a keyboard in Sydney
The Origin hack is the biggest high-profile incident since Partnered Health revealed a breach. (Dan Himbrechts/AAP PHOTOS)

Griffith University's Graeme Hughes, an expert on business and consumer issues, said the breach was unlikely to cause cases of payment fraud but marked a "social engineering problem".

"The last four digits for a card, a date of birth, and an authentic billing history are the exact trust signals a businesses uses to verify itself over the phone," Professor Hughes told AAP.

"That makes an unsolicited call about an energy account far more convincing than it should be.

"If comparable Australian breaches have taught us anything, the confirmed scope (of the breach) usually widens rather than narrows."

The breach represents the country's most high-profile cyber incident since Partnered Health, owned by private equity firm Quadrant, said earlier in July that its medical records were breached clinics in Sydney, Melbourne and Canberra.

In 2025, airline Qantas said it had customer data published by cybercriminals, while telco giant Optus and health insurer Medibank were hit in attacks in 2022 that sparked cyber-resilience laws.

License this article

Sign up to read this article for free
Choose between a free or paid subscription to AAP News
Start reading
Already a member? Sign in here
Top stories on AAP right now