EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-origin-energy-breach
022/430

File EL-0409HighOngoing / ContainedData Breach / Unauthorised Access / Extortion

Origin Energy Data Breach

Also filed as Origin Energy Customer Data Hack · Origin Energy Kraken System Breach

Unauthorised access to Origin Energy customer systems resulting in the exposure of personal and partial financial data belonging to a significant portion of its Australian customer base.

  • #energy-sector
  • #pii
  • #customer-records
  • #partial-banking-details
  • #australia
  • #utilities
Notoriety8/10
Event
2 Jul 2026
Disclosed
22 Jul 2026
Target
Origin Energy
Actor
Unknown (claimed as Edison Walthour / John Doe)
Scale
900K people
Status
Ongoing / Contained

01Summary

In July 2026 Origin Energy confirmed unauthorised access and disclosure of some customer data. A person claiming responsibility (using aliases including Edison Walthour and John Doe) stated they had accessed approximately 2 million customer records via an employee login linked to Origin’s customer management system (supplied by technology provider Kraken). The actor claimed to have contacted Origin privately from early July before going public. Origin confirmed the data exposure on 23 July and stated it was still determining the exact number of impacted customers. The claimed actor later stated a private settlement had been reached and that the data would not be leaked.

02Background

Origin Energy is one of Australia’s largest electricity and gas retailers, serving approximately 4.8 million customer accounts across electricity, gas, LPG and internet services.

03Key revelations

  1. 01Access allegedly obtained through lingering employee/former-employee credentials on a third-party customer management platform (Kraken).
  2. 02Partial payment details (last 4 of cards / last 3 of bank accounts) were among the exposed fields.
  3. 03Origin's investigation confirmed about 900,000 current and former customers were affected, fewer than the 2 million the actor claimed.

04Technical analysis

Alleged initial access via an employee (or former employee) login credential connected to the Kraken customer management platform. Exact vulnerability or misconfiguration details have not been publicly confirmed by Origin.

Attack vector
Compromised employee / former employee credentials (alleged)
Attack method
Unauthorised access and data exfiltration followed by extortion attempt
Initial access
Valid Accounts (compromised credentials)
Exfiltration
Direct data access / download

05Threat actor

Individual actor (or small operation) using aliases Edison Walthour / John Doe; claimed private settlement rather than public leak.

Aliases

  • Edison Walthour
  • John Doe

Attribution sources

  • Media reports (The Australian, 7NEWS, Sky News)
  • Origin ASX statements

06Victims and impact

Countries affected

  • Australia

07Data exposed

Data types

  • PII
  • Names
  • Addresses
  • Dates of birth
  • Phone numbers
  • Account information
  • Partial credit card numbers (last 4)
  • Partial bank account numbers (last 3)

08Financial damage

Possible regulatory action by the OAIC, plus customer notification and support costs, including a 12-month Equifax Protect subscription and IDCARE support for affected customers. The actor claimed 2 million records and a private settlement, but Origin's investigation confirmed about 900,000 current and former customers.

09Timeline

  1. 2026-07-02Alleged initial contact by threat actor to Origin (per media reports).
  2. 2026-07-22Origin announces investigation into potential security incident.
  3. 2026-07-23Origin confirms unauthorised access and disclosure of some customer data.
  4. 2026-07-24Claimed actor states private settlement reached and data will not be leaked.
  5. 2026-07-28Origin confirms about 900,000 current and former customers were affected and offers Equifax Protect and IDCARE support.

10On the record

I’m sorry this has happened. Customers trust Origin with their information, and I apologise for the impact this may cause.

Frank Calabria (Origin CEO), ASX statement 23 July 2026

11Reaction and fallout

Public reaction

Customer concern over timing of notifications and exposure of partial banking details; media focus on credential hygiene and third-party platform risk.

12Legal

Investigation ongoing; notifications to ACSC, AFP and OAIC.

13Aftermath

Security improvements

  • Engagement of independent cyber experts
  • System securing and access reviews underway

14Significance and legacy

Significance

Major Australian energy retailer breach involving millions of customer records and partial financial data, highlighting ongoing risks around third-party customer platforms and credential lifecycle management.

15Disclosure and media

Publishing organisations

  • The Guardian
  • ABC News
  • 7NEWS
  • Sky News Australia
  • The Australian
  • SecurityWeek

16Related files

Related events

  • 2026-centerpoint-energy-breach

17Field notes

  1. 01Threat actor claimed access via Origin’s Kraken customer management system.
  2. 02Origin has approximately 4.8 million customer accounts.

18Resolution

Origin confirmed unauthorised access and disclosure. The claimed actor said a private settlement was reached and the data would not be leaked. By August 2026 Origin had contacted about 900,000 affected current and former customers and was sending each one a notice of the specific information accessed.

19Sources

Official documents

  • Origin Energy ASX announcements (22 & 23 July 2026)
  • Origin Energy customer update page

References

  1. [1]Origin Energy official statements
  2. [2]The Guardian
  3. [3]ABC News
  4. [4]SecurityWeek
  5. [5]7NEWS
  6. [6]Sky News Australia
  7. [7]ABC News: https://www.abc.net.au/news/2026-07-28/origin-energy-data-breach-900k-customers-impacted/106961804
  8. [8]Origin Energy: https://www.originenergy.com.au/about/investors-media/update-on-data-security-incident/
Fact sheetEL-0409

Dates

Event
2 Jul 2026
Started
2 Jul 2026
Discovered
22 Jul 2026
Disclosed
22 Jul 2026
Ongoing
Yes

Target

Organisation
Origin Energy Limited
Type
Energy Retailer / Utility
Sector
Energy & Utilities
Country
Australia

Actor

Name
Unknown (claimed as Edison Walthour / John Doe)
Type
Individual / Criminal Actor
Motivation
Financial gain through extortion; claimed private settlement with Origin.
Attribution
Low-Medium
Status
Active / Claimed settlement
Arrested
No
Convicted
No

Data

People
900,000
Records
900,000
Sensitivity
High
Published
No
Sold (dark web)
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.