July 23, 2026
I Got the Origin Energy Breach Email.
On Wednesday night I opened my inbox and found an email from Origin Energy with a subject line nobody wants to see: “Potential customer…

By Sayan Raha
6 min read
I Got the Origin Energy Breach Email. Here's What It Actually Means — and the 10 Things You Should Do Right Now
On Wednesday night I opened my inbox and found an email from Origin Energy with a subject line nobody wants to see: "Potential customer data security incident."
It was carefully worded. Origin was investigating. Something may have involved unauthorized access. And — the line I clung to — the company did not believe credit card or bank details were caught up in it.
Twenty-four hours later, that last part changed.
If you're one of Origin's roughly 4.8 million customer accounts, here's what actually happened, what's still unknown, and — most importantly — the concrete steps worth taking today.
The timeline so far
Wednesday 22 July. Origin emailed customers to say it was investigating a potential security incident that might involve unauthorized access to customer information. It said it had engaged the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner. It also said it did not believe credit card or bank details were affected.
Thursday 23 July. Origin updated the market and its incident page. This time the language was firmer: the company confirmed there had been unauthorized access to, and disclosure of, some customers' data.
For affected customers, the potentially exposed information may include:
- Full name
- Residential address
- Date of birth
- Contact phone number
- Account information
- The last four digits of a credit card, or the last three digits of a bank account
Origin's point — a fair one — is that partial card and account numbers can't be used on their own to make purchases or access accounts. CEO Frank Calabria apologized and said securing systems against further access was a top priority, with independent cyber experts brought in alongside the authorities.
Still unknown: how many customers are affected. Origin says it is working that out and will contact people directly where it can confirm they were impacted.
The part that isn't confirmed
Running alongside the official statements is a claim from someone identifying themselves as "John Doe," who told media they had accessed the personal details of more than two million Origin customers. They reportedly provided a sample of 50 customer records to a newspaper and started a 14-day countdown, threatening to publish the data if Origin doesn't make contact.
Treat this as an allegation, not a fact. Origin has not confirmed the figure or the framing. But it's worth naming for one reason: security researchers who've watched Australian breaches play out — Optus, Medibank, Qantas — have a consistent observation, which one expert put plainly this week: the confirmed scope of these incidents tends to grow over time, not shrink.
Plan for the possibility that more is exposed than has been announced. That's not panic. It's just cheap insurance.
Why "only the last four digits" is not as harmless as it sounds
This is the part I think most coverage under-explains.
You will probably not be defrauded directly with the last four digits of your card. Nobody is buying a laptop with that.
The real risk is social engineering. Think about what a scammer now potentially holds: your name, your address, your date of birth, your phone number, your Origin account number, and the last four digits of the card you pay your electricity bill with.
Those are precisely the details a legitimate business uses to prove to you that it's legitimate. Griffith University's Professor Graeme Hughes made this point to AAP this week — that combination turns an unsolicited phone call about your energy account into something far more convincing than it has any right to be.
So the attack that follows a breach like this usually isn't a fraudulent transaction. It's a phone call:
"Hi, it's Origin, calling about the security incident. I can verify your account — you're at [your address], date of birth [correct], and the card ending [correct four digits]. We need to move your direct debit to a new secure payment method."
Everything checks out. That's the trap. The verification details are the stolen goods.
Expect a wave of Origin-branded phishing emails and SMS in the coming weeks, too. Breach notifications are catnip for scammers, because they give a plausible reason to contact you urgently about your account.
The 10 things to do if you get a breach email like this
This checklist applies to the Origin incident, but it works for any "we've had a data security incident" email you'll ever receive.
1. Verify the email before you act on it — without clicking it
The single most important habit. Don't click the links in a breach notification, even a real one. Open a browser, type the company's domain in yourself, and find the incident page. Origin's is at originenergy.com.au. If the email is real, the same information will be there. If it isn't there, the email is fake.
Check the sender's domain too, character by character. Origin's genuine notice came from an @originenergy.com.au address. Scammers use lookalikes — extra hyphens, .net instead of .com.au, a subdomain that reads right at a glance.
2. Assume the scope will grow
Don't wait for a personal "you were affected" notification to start protecting yourself. Origin has said it will contact confirmed-affected customers, but that process takes time and the picture is still forming. Act as though your data is out.
3. Change your account password — and anywhere you reused it
Change your Origin account password. Then be honest with yourself about where else that password lives. If it's on your email, your banking, or your shopping accounts, change those too. Credential stuffing — trying a leaked password across dozens of other services — is automated and cheap.
Use a password manager so every account gets a different password. This one change does more for your security than everything else on this list combined.
4. Turn on multi-factor authentication everywhere that matters
Email first, then banking, then everything else. Your email account is the master key — whoever controls it can reset the passwords on everything else. Prefer an authenticator app over SMS codes where you have the option.
5. Adopt one hard rule for inbound contact
Never verify your identity to someone who called you.
If you get a call, text or email about your account, hang up or close it, then contact the company yourself using a number from their official website or your paper bill. Never a number supplied in the message. A real organisation will never be annoyed by this. A scammer will pressure you not to do it.
6. Watch your accounts, not just your card
Set up transaction alerts with your bank. Check statements weekly for a while — including small amounts. Testing a card with a $1 charge before a large one is standard practice for fraudsters.
7. Consider a credit ban with the credit bureaus
In Australia you can request a free credit ban (a suppression) through Equifax, Experian and illion. It stops new credit being opened in your name, lasts 21 days by default, and can be extended. If your name, address and date of birth are exposed, this is the strongest single protective step available for identity theft — and it costs nothing.
You can also request a free copy of your credit report from each bureau to check for accounts you don't recognise.
8. Be sceptical of "help" that arrives unsolicited
After every major breach, a secondary industry of fake identity-protection services springs up. If Origin offers credit monitoring, take it up through Origin's own website. Don't sign up for anything pitched to you in an unsolicited email or ad.
9. Know who to call — and use them, they're free
- IDCARE (idcare.org) — Australia and New Zealand's national identity and cyber support service. Free, and they'll build a personal response plan with you. This is the single best resource if you think your identity has been misused.
- Scamwatch / National Anti-Scam Centre (scamwatch.gov.au) — report scam contact.
- Australian Cyber Security Centre (cyber.gov.au) — practical guidance and incident reporting.
- ReportCyber — for reporting cybercrime to police.
10. Document everything
Keep the original breach email. Save screenshots of anything suspicious you receive afterwards. Note dates and times of calls. If something does go wrong later, a paper trail makes disputes with banks — and any future complaint to the OAIC — dramatically easier.
The bigger question
Optus. Medibank. Latitude. Qantas. Now Origin. The list of Australian companies that have lost their customers' personal data is long enough that "assume it's already out there" is the only rational default position for anyone living here.
That should reframe how we think about this. The goal isn't to keep your data secret — that battle is largely lost. The goal is to make your data useless to whoever holds it: unique passwords so a leak doesn't cascade, MFA so a password isn't enough, credit bans so your identity can't be monetised, and a personal rule against verifying yourself to inbound callers so social engineering has nothing to work with.
None of that requires trusting a company to protect you. That's the point.
About the Author
Sayan Raha is a Cybersecurity Lead specialising in Data Security, Microsoft Purview, AI Security Governance, GRC, and enterprise cyber resilience. He writes about cybersecurity, emerging threats, AI governance, and practical security strategies for organizations and individuals.
This post reflects publicly available information as of 24 July 2026. Origin's investigation is ongoing and the details may change — check originenergy.com.au for the current official update. Nothing here is financial or legal advice; if you believe your identity has been misused, contact IDCARE and your bank directly.