Australia's largest energy provider has suffered a devastating cyber attack, exposing personal and banking details of nearly five million customers. The breach, which is being investigated by authorities, raises serious concerns about the security of data held by major utility companies around the world – including in the UK, where many households rely on similar services.
Origin Energy, which provides electricity, natural gas, LPG, and internet services to 4.8 million accounts across Australia, confirmed that hackers accessed customer names, addresses, dates of birth, contact phone numbers, and Origin account information. Moreover, the last four digits of some credit cards or the last three digits of bank accounts were also compromised – a worrying development for customers who may be vulnerable to identity theft and targeted phishing attempts.
Origin Energy's chief executive, Frank Calabria, has apologised for the incident, acknowledging that customers trust the company with their sensitive information. The firm is working closely with independent cyber experts and Australian authorities, including the Australian Cyber Security Centre, the Australian Federal Police, and the Office of the Australian Information Commissioner (OIAC), to investigate the hack and bolster its systems against further unauthorised access.
The breach follows a string of high-profile data breaches in Australia, including a leak of 5 million Qantas customers' information in October 2025. This latest incident has prompted warnings about potential scam calls, with OIAC reporting a significant increase in data breach notifications last year – 1,205 incidents, 716 of which were attributed to malicious or criminal activity.
The repeated nature of these breaches raises concerns about the robustness of data protection measures within large organisations, particularly those handling sensitive customer information for essential services. As a result, British households should be aware that similar risks may exist in their own energy providers – sparking questions about the adequacy of UK's data protection laws and regulations to safeguard customers' personal data.