Origin Energy data breach: were my details in the 900,000 affected?
If you are a customer of Origin Energy, here’s what is being claimed, and what it would mean for you.
Origin Energy has confirmed that about 900,000 current and former customers had personal information accessed in a July 2026 incident. Most records included name, address, date of birth, phone number and partial payment details; about 60 included a full bank-account number. Origin says it has contacted those customers and is offering 12 months of credit-monitoring.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Origin Energy customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
On 21 August 2026, Origin Energy said its review of a July incident was substantially complete. About 900,000 current and former customers had information accessed without authorisation. Origin has contacted them and is sending each person a notification that matches their own record.
For most people, that information was some mix of name, address, date of birth, phone number, account details, other personal circumstances they had shared with Origin, and the last four digits of a credit card or last three digits of a bank account. About 60 customers had a full bank-account number accessed; about 100 had an ID-document number (the number only, no scan); about 15,000 had a government concession or program number. Origin first raised a possible incident on 22 July, confirmed unauthorised access on 23 July, and published the 900,000 figure on 28 July. It has notified Australia's privacy and cyber authorities and the Federal Police. A criminal investigation is continuing.
Why “only 60 bank accounts” misses the point
Almost every report of this incident leads with 900,000 people and then immediately softens it: only about 60 had a full bank-account number taken. That figure is real. Origin published it. If you read it as permission to relax, you are reading the story the way the coverage is shaped, not the way a stranger with the file would use it.
What that stranger actually holds, for the great majority of those 900,000 people, is a working identity kit: a name, a home address, a date of birth, a phone number that reaches you, enough account detail to talk about an Origin bill, and the last few digits of a card or bank account. Those last digits are the same fragment companies often ask for to “confirm it is you”. Origin also said the records included other details about personal circumstances customers had chosen to share with their energy retailer.
This is not a dump of passwords or full credit-card numbers. It is the raw material of a convincing phone call. Someone who already knows where you live, when you were born, and part of how you pay can impersonate Origin, a bank, or a government office with far less guesswork. The 60 full bank-account numbers, the 100 ID numbers and the 15,000 concession numbers are the sharper end. They are not the only end that matters. Former customers are in this set too; leaving Origin does not take you out of it.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
What to actually expect
- If you are a current or former Origin customer and you were among the 900,000, Origin says it has already been in touch and is issuing a notification specific to your record. That is the only reliable way to know. Nobody else can honestly tell you whether you were in this incident, and no online scan can either. A message that asks you to click or call back to “see if you were affected” is not Origin’s notification.
- In the coming weeks, expect calls, texts and emails that already know something true about you — your name, your suburb, part of an account or card number — and that urge you to verify, claim a refund, or lock something down. Some of that will be people riding the news; some of it may use this data. Either way, do not give more information or make a payment because the caller already had a few facts right.
- Origin is offering identity-monitoring and 12 months of credit-monitoring. The useful thing to watch there is a credit application or a new account you did not open. A sudden charge on a card you already have is less likely from this incident, because full card numbers were not what Origin described for the main group.
- If Origin’s notification says your full bank-account number, an ID-document number, or a concession number was involved, you are in the smaller group. Treat that number as known to someone who should not have it, and deal with that bank or agency first.
What you can and cannot fix
What left Origin cannot be pulled back. If your name, home address, date of birth, phone number, account details, or those last few card or bank digits were in the accessed records, they are out. So are any personal circumstances you had shared with the company. Origin cannot recall them. No removal service can either. A date of birth does not change. An address you still live at is still your address.
For about 60 people, a full bank-account number is out. For about 100, an ID-document number is out. For about 15,000, a government concession or program number is out. Those numbers cannot be un-known.
- Treat inbound contact about this claimed breach as untrusted. If you need to speak to Origin or your bank, start from an app, a bill, or a phone number you already had — not from a link or a number in a message that arrived this week.
- Use the monitoring Origin is providing. Twelve months of credit-monitoring is the practical check for someone trying to open credit in your name with a real date of birth and address. Enrol if you are offered it, and actually look at the alerts.
- If Origin told you a full bank-account number or ID number was involved, deal with that number. Ask the bank whether the account should be replaced. Be slower to accept that ID number, on its own, as proof of who you are.
- Shrink the rest of your public file. A leaked name, address and date of birth becomes much more dangerous when it is joined to people-search and data-broker listings that add relatives, extra phone numbers, employers and previous addresses. Those listings, unlike the Origin data, can actually be taken down. That is the lever that remains: make the leaked record harder to build on.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Origin Energy.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…
PayPal SSN Exposure Lasting Six Months — February 2026
A code change at PayPal allowed unauthorized access to Social Security Numbers and account details f…
Was I in the SafePal data breach? What they took and what they didn't
On 16 August 2026 SafePal said a flaw in its order-tracking plug-in exposed names, emails, shipping …