{"id":77161,"date":"2026-08-21T06:10:12","date_gmt":"2026-08-21T06:10:12","guid":{"rendered":"https:\/\/www.europesays.com\/australia\/77161\/"},"modified":"2026-08-21T06:10:12","modified_gmt":"2026-08-21T06:10:12","slug":"dozens-of-origin-energy-customers-full-bank-details-id-numbers-accessed-in-july-breach","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/australia\/77161\/","title":{"rendered":"Dozens of Origin Energy customers&#8217; full bank details, ID numbers accessed in July breach"},"content":{"rendered":"<p class=\"paragraph_paragraph___QITb\">Origin Energy says as many as 60 customers had their full bank account numbers accessed by a hacker in July.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Last month, Origin confirmed a major cybersecurity breach affecting approximately 900,000 current and former customers.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The company has also updated the public, saying that for those 900,000 customers affected by the July security breach, information accessed included some combination of name, address, date of birth, contact phone number, account and other information about the customers&#8217; personal circumstances, as well as the last four digits of a credit card, or the last three digits of a bank account.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The hacker, Origin has confirmed, also accessed &#8220;numbers associated with government concession scheme or program, affecting approximately 15,000 customers in total&#8221;.<\/p>\n<p class=\"paragraph_paragraph___QITb\">In addition, approximately 100 customers have had an &#8220;ID document number&#8221; accessed, stressing it was &#8220;the number only, no scanned copies of ID documents were affected&#8221;.<\/p>\n<p><a href=\"https:\/\/www.abc.net.au\/news\/2026-07-24\/origin-breach-could-fuel-wave-of-ai-powered-scams\/106951588\" data-component=\"FullBleedLink\" class=\"RelatedCard_link__rsgR9 FullBleedLink_root__lTw_U interactive_focusContext__yRhc_ interactive_defaults__AKxUU FullBleedLink_showVisited__g3Xvz\" rel=\"nofollow noopener\" target=\"_blank\">AI has changed what criminals can do with your stolen Origin data<\/a><\/p>\n<p class=\"Typography_base__sj2RP RelatedCard_synopsis__cFwMW Typography_sizeMobile14__u7TGe Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">The theft of names, addresses and phone numbers may seem less serious than stolen bank details, but cyber experts say AI is changing what criminals can do with that information.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;We have now confirmed the specific types of information that have been accessed on a customer-by-customer basis, and are well advanced in providing further specific notifications to each affected customer,&#8221; the company said in a statement.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Those specific customer notifications include details of the information that has been accessed, advice on the practical steps they can take and the various supports available.&#8221;<\/p>\n<p class=\"paragraph_paragraph___QITb\">The criminal investigation into the breach is still ongoing, Origin Energy CEO Frank Calabria said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;We have substantially completed our review into the information accessed for each affected customer, and our priority is completing our notifications to them and providing support,&#8221; he said in a statement.<\/p>\n<p>&#8220;We have taken several steps to enhance the security of our systems to prevent future incidents of this kind.&#8221;<\/p>\n<p class=\"paragraph_paragraph___QITb\">He added that the company is working closely with the federal government, the Australian Cyber Security Centre, the National Office of Cyber Security and the Australian Federal Police.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The update from the energy company comes after <a class=\"Link_link__kR0xA Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.abc.net.au\/news\/2026-08-18\/origin-energy-hack-traced-to-accenture-manila-office\/107049188\" data-component=\"Link\" data-uri=\"coremedia:\/\/article\/107049188\" rel=\"nofollow noopener\" target=\"_blank\">authorities traced the cyber hack to a call centre in the Philippines<\/a>, with the investigation linking the breach to a former Accenture employee in Manila.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Accenture works with Origin to run its call centres, but a spokesperson for the company declined to comment on the Origin incident when contacted by the ABC on Tuesday.<\/p>\n<p><img decoding=\"async\" alt=\"The orange Origin Energy logo on the outside of the business with traffic lights and street signs in the foreground.\" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.europesays.com\/australia\/wp-content\/uploads\/2026\/08\/5fd4c66cc16b2902e752e2cc4f2e0a14.jpeg\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">The criminal investigation into the data breach is ongoing. (AAP: Jay Kogler)<\/p>\n<p>Putting &#8216;legal defence&#8217; before customers<\/p>\n<p class=\"paragraph_paragraph___QITb\">On Friday, Origin Energy confirmed to the ABC that the alleged hacker had not leaked or disclosed any customer data to the public.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Despite this, Origin has provided several support options for affected customers, including identity monitoring and 12 months of free credit monitoring.\u00a0<\/p>\n<p class=\"paragraph_paragraph___QITb\">The company has also recommended customers be cautious of any unusual or suspicious activity, particularly in communications that appear to come from Origin, the government, or their bank.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Cyber security expert Troy Hunt criticised the latest update from Origin on Friday, saying it and other large corporations are taking too long to inform and update customers potentially affected by a hack.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;[Origin is] saying a lot [in this latest announcement] without saying much,&#8221; he told the ABC.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Organisations are saying less and less, which is a shame.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;I would have liked to have understood a little more about the hack.&#8221;<\/p>\n<p><img decoding=\"async\" alt=\"A man in a t shirt sat in front of a computer screen\" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.europesays.com\/australia\/wp-content\/uploads\/2026\/08\/58752ddd4058ca0fea4e552e25f7b0d1.jpeg\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Troy Hunt says large corporations need to better communicate with affected customers. (ABC News: Jessica Lamb)<\/p>\n<p class=\"paragraph_paragraph___QITb\">Mr Hunt believes large publicly-listed organisations too often prioritise information management over customer needs.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Within these organisations there is a big component of trying to preserve shareholders&#8217; value,&#8221; Mr Hunt said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Their primary accountability is not shareholders, not customers.<\/p>\n<p>&#8220;These responses are about preparing for a legal defence than prioritising customers.&#8221;Executive bonuses slashed after breach\u00a0<\/p>\n<p class=\"paragraph_paragraph___QITb\">In its latest annual report published last Thursday, Origin Energy confirmed its executive managers would have their bonuses reduced as a result of the data breach.<\/p>\n<p class=\"paragraph_paragraph___QITb\">It noted the board determined docking bonus pay would appropriately reflect &#8220;shared accountability and to recognise the large number of customers involved and the importance of the security of our systems and customer data&#8221;.<\/p>\n<p class=\"paragraph_paragraph___QITb\">That saw CEO Frank Calabria&#8217;s pay reduced by $357,000, and other executive management reduced by $607,000.<\/p>\n<p class=\"paragraph_paragraph___QITb\">But the board said it would consider future financial penalties against executives once all reviews and investigations had been completed.<\/p>\n<p class=\"paragraph_paragraph___QITb\">It was the only financial mention of the data breach in its results, with the company noting it would be included in its results for the 2027 financial year instead.<\/p>\n<p><a href=\"https:\/\/www.abc.net.au\/news\/2026-08-10\/australias-largest-data-breaches-compared-to-origin-leak\/106971048\" data-component=\"FullBleedLink\" class=\"RelatedCard_link__rsgR9 FullBleedLink_root__lTw_U interactive_focusContext__yRhc_ interactive_defaults__AKxUU FullBleedLink_showVisited__g3Xvz\" rel=\"nofollow noopener\" target=\"_blank\">Australia&#8217;s largest data breaches<\/a><\/p>\n<p class=\"Typography_base__sj2RP RelatedCard_synopsis__cFwMW Typography_sizeMobile14__u7TGe Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Origin Energy recently announced that 900,000 current and former customers had their personal data leaked. But what have we learnt since?<\/p>\n<p>\u00a0<\/p>\n<p class=\"paragraph_paragraph___QITb\">The breach was first reported by The Australian in July, when the alleged hacker sent a sample of 50 customer records containing names, addresses, emails, dates of birth, phone numbers and billing histories.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Only after The Australian sent that information to Origin Energy did the company alert authorities to a potential security breach.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The data breach is believed to be the largest known incident experienced by an Australian energy retailer. A cyber incident in September 2022 resulted in details of <a class=\"Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.energyaustralia.com.au\/about-us\/media\/news\/energyaustralia-implements-additional-password-complexity-my-account-following\" data-component=\"Link\" rel=\"nofollow noopener\" target=\"_blank\">hundreds of EnergyAustralia customers being exposed<\/a>.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Origin Energy customers had reported delays in receiving their energy bills in the days before the data breach was confirmed. However, the company said it was not connected to the incident.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Origin is one of several major Australian companies to experience a security breach, after Qantas suffered a major hack in 2025 and Optus and Medibank experienced breaches in 2022.<\/p>\n<p class=\"paragraph_paragraph___QITb\">On Wednesday, <a class=\"Link_link__kR0xA Link_link__5eL5m ScreenReaderOnly_srLinkHint__OysWz Link_showVisited__C1Fea Link_showFocus__ALyv2\" href=\"https:\/\/www.abc.net.au\/news\/2026-08-19\/quest-apartment-hotels-data-security-breach\/107053574\" data-component=\"Link\" data-uri=\"coremedia:\/\/article\/107053574\" rel=\"nofollow noopener\" target=\"_blank\">Quest Apartment Hotels became the latest business to experience a security breach<\/a> that affected customers&#8217; data.<\/p>\n<p>Loading&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"Origin Energy says as many as 60 customers had their full bank account numbers accessed by a hacker&hellip;\n","protected":false},"author":2,"featured_media":77162,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[115244,5866,5263,5327,10620,115245,31269,260,115242,113344,115243,31953,23990],"class_list":["post-77161","post","type-post","status-publish","format-standard","has-post-thumbnail","category-melbourne","tag-accenture","tag-call-centre","tag-cyber-security","tag-cybersecurity","tag-data-breach","tag-frank-calabria","tag-hack","tag-melbourne","tag-origin-data-breach","tag-origin-energy","tag-origin-hack","tag-philippines","tag-scams"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/australia\/wp-json\/wp\/v2\/posts\/77161","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/australia\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/australia\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/australia\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/australia\/wp-json\/wp\/v2\/comments?post=77161"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/australia\/wp-json\/wp\/v2\/posts\/77161\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/australia\/wp-json\/wp\/v2\/media\/77162"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/australia\/wp-json\/wp\/v2\/media?parent=77161"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/australia\/wp-json\/wp\/v2\/categories?post=77161"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/australia\/wp-json\/wp\/v2\/tags?post=77161"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}