Executive Summary
On 28 July 2026, Origin Energy publicly confirmed a significant data breach affecting approximately 900,000 current and former customers. The breach resulted in unauthorized access and exfiltration of personally identifiable information (PII), including names, addresses, dates of birth, phone numbers, account details, and partial payment information such as the last four digits of credit cards or the BSB and last three digits of bank accounts. The incident was first identified as a potential threat in early July 2026, but only confirmed as a credible security incident on 22 July 2026, with public disclosure and customer notification following shortly thereafter. The breach is currently under investigation by Australian authorities, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police, and the Office of the Australian Information Commissioner. No technical indicators of compromise (IOCs) have been published as of the date of this report. All facts in this summary are corroborated by the official Origin Energy disclosure (Origin Energy, 28 July 2026), ABC News (ABC News, 28 July 2026), and Nine.com.au (Nine.com.au, 28 July 2026).
Technical Information
The Origin Energy data breach represents a major compromise of customer data within the Australian energy sector, a critical infrastructure domain. The breach involved unauthorized access to systems containing sensitive customer information. The types of data confirmed as compromised include names, addresses, dates of birth, phone numbers, account information, and partial payment details (last four digits of credit cards or the BSB and last three digits of bank accounts) (Origin Energy, 28 July 2026; Nine.com.au, 28 July 2026).
Attack Vector Analysis
The specific technical vector used to gain initial access remains undisclosed. Origin Energy began reviewing a "potential security threat" in early July 2026, which was initially not deemed credible (Origin Energy, 28 July 2026; ABC News, 28 July 2026). On 22 July, new information indicated a security incident had occurred, prompting immediate action and notification of authorities. An alleged hacker provided a media outlet with a sample of 50 customer records and screenshots of internal Origin Energy systems (ABC News, 28 July 2026). However, no technical artifacts such as phishing emails, malware samples, or exploited vulnerabilities have been disclosed. As a result, attribution to a specific attack vector (such as phishing, credential stuffing, or vulnerability exploitation) is not possible based on available evidence. The technical confidence level for initial access is low due to the absence of direct evidence.
Data Exfiltration
It is confirmed that customer data was accessed and exfiltrated, as evidenced by the sample data provided to media and Origin Energy's own disclosure (Origin Energy, 28 July 2026; ABC News, 28 July 2026). The technical confidence level for data exfiltration is high, with multiple independent sources confirming unauthorized access and exfiltration of customer data.
Malware and Tools Identified
No malware, hacking tools, or specific technical indicators have been disclosed by Origin Energy, law enforcement, or independent media as of 28 July 2026 (Origin Energy, 28 July 2026; ABC News, 28 July 2026; Nine.com.au, 28 July 2026). The technical confidence level for the absence of evidence is high.
MITRE ATT&CK Mapping
Based on confirmed facts, the following MITRE ATT&CK techniques are most likely involved:
For Initial Access (TA0001), T1078 (Valid Accounts) and T1190 (Exploit Public-Facing Application) are possible, but only circumstantial evidence exists, resulting in low confidence. For Collection (TA0009), T1005 (Data from Local System) is confirmed with high confidence, as the attacker accessed and collected customer data from Origin Energy's systems. For Exfiltration (TA0010), T1041 (Exfiltration Over C2 Channel) or T1567 (Exfiltration Over Web Service) are confirmed with high confidence, as data was exfiltrated and provided to media. No evidence of destructive or disruptive impact (such as resource hijacking or denial of service) has been observed.
Threat Actor Attribution
No technical indicators (malware, infrastructure, or TTPs) have been published that would allow attribution to a known threat actor or group. The attack is classified as a "criminal matter" under investigation by Australian authorities (Origin Energy, 28 July 2026; ABC News, 28 July 2026). An individual claiming responsibility contacted media and provided sample data, but their identity and affiliation are unconfirmed. The confidence level for attribution is low.
Historical Context and Sector Targeting
The Australian energy sector has been targeted in previous cyber incidents, including ransomware and data theft campaigns (see: Australian Cyber Security Centre Annual Cyber Threat Report). However, no direct links to previous incidents or known threat actors have been established in this case. The sector is a known target, but no direct linkage exists for this incident.
Origin Energy is a major energy provider, making it a high-value target for both financially motivated and state-sponsored actors (Origin Energy, 28 July 2026). The data types targeted—PII and partial financial data—are consistent with patterns observed in other Australian critical infrastructure breaches.
Affected Versions & Timeline
The breach affected approximately 900,000 current and former customers of Origin Energy. The timeline of the incident is as follows: In early July 2026, Origin Energy began reviewing a potential security threat, which was initially not deemed credible. On 22 July 2026, new information emerged indicating a potential security incident, prompting immediate action and notification of authorities. On 23 July 2026, unauthorized access and disclosure of customer data were confirmed. On 28 July 2026, Origin Energy completed the initial phase of its review and publicly confirmed the number of affected customers and support measures (Origin Energy, 28 July 2026; ABC News, 28 July 2026; Nine.com.au, 28 July 2026).
Threat Activity
The threat activity involved unauthorized access to Origin Energy's systems and exfiltration of customer data. The breach was first identified as a potential threat in early July 2026, but only confirmed as a credible security incident on 22 July 2026. An individual claiming responsibility contacted media outlets and provided sample data and screenshots of internal systems, but their identity and affiliation remain unconfirmed (ABC News, 28 July 2026). The incident is classified as a criminal matter and is under investigation by multiple Australian authorities. No evidence of destructive or disruptive activity has been observed; the breach was limited to data theft.
Mitigation & Workarounds
Origin Energy has taken several steps to mitigate the impact of the breach and support affected customers. The following actions have been confirmed:
The company has extended customer support hours and established a dedicated contact number for the incident. Specialist identity and cyber support services, including a 12-month subscription to Equifax Protect and support from IDCARE, have been made available to affected customers. Origin Energy is working with cybersecurity and forensic specialists to ensure the incident is contained and has taken steps to secure its systems. The company is also working closely with the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police, and the Office of the Australian Information Commissioner (Origin Energy, 28 July 2026).
Customers are advised to remain vigilant for suspicious activity, including phishing attempts and scams that may exploit the breach. No technical workarounds or patches have been disclosed, as the specific attack vector remains unknown.
Indicators of Compromise
No public indicators of compromise (IOCs) were available at the time of writing. Organizations should continue to monitor official sources for updates and validate any future indicators before enforcement.
References
Origin Energy, 28 July 2026 – Official Disclosure
ABC News, 28 July 2026 – Origin Energy believes 900,000 customers' data accessed in breach
Australian Cyber Security Centre Annual Cyber Threat Report
About Rescana
Rescana provides a third-party risk management (TPRM) platform designed to help organizations identify, assess, and monitor cyber risks in their supply chain and vendor ecosystem. Our platform enables continuous risk assessment, automated evidence collection, and actionable insights to support incident response and compliance efforts. For questions regarding this report or to discuss how Rescana can support your organization’s risk management needs, please contact us at info@rescana.com.



