Origin Energy Breach: The Second Wave Is a Phone Call

Australia's largest electricity and gas retailer is investigating a major data breach. The stolen records reportedly include names, addresses, dates of birth, phone numbers and the last few digits of card and bank accounts - which is precisely enough to make a scam call sound legitimate. The breach is the headline. The second wave is a phone call to your accounts team, and it has not arrived yet.

Security · Data Breach · Scam Calls

The Breach Was the Headline. The Second Wave Is a Phone Call to Your Accounts Team

Australia’s largest energy retailer is investigating a major data breach, and the details taken are unusually rich. The part that reaches your business arrives later, by phone, from someone who already knows the last four digits of the card.

📅 ⏱ 13 min read 🇦🇺 Australian owned · we own and operate our own network
TL;DR

Origin Energy confirmed in late July 2026 that customer data had been accessed in a breach now under examination by Australian authorities. Origin said the data may include name, address, date of birth, contact phone number and account information, plus the last four digits of a credit card or last three of a bank account. Origin has around 4.8 million customers and has not confirmed the number affected; the person claiming responsibility told a newspaper he held about two million records, and later reporting put the figure closer to 900,000. The Australian Cyber Security Centre, National Office of Cyber Security, AFP and OAIC are involved. Why it matters to you: those partial payment digits are the exact detail a legitimate organisation uses to prove it is legitimate, so they turn the standard verification ritual into the attack. Generative AI has removed the effort barrier that once kept targeted fraud rare, so “spot the badly written email” no longer works. This guide covers what is confirmed, the six approaches your staff will actually encounter, Australia’s regulatory position in 2026, the phone-side controls that help, and the one verification rule that defeats nearly all of it.

What Origin Has Confirmed

Origin Energy is Australia’s largest electricity and gas retailer, with roughly 4.8 million customers. In late July 2026 it confirmed that customer data had been accessed and taken in a cyber incident, after the individual claiming responsibility approached The Australian newspaper with sample data and screenshots said to come from internal systems.

PointWhat is known
Data involved Origin said it may include name, address, date of birth, contact phone number and account information, plus the last four digits of a credit card or the last three digits of a bank account.
Timeline Raised internally as a potential issue in early July 2026, assessed as credible around 22 July, publicly confirmed with customer notifications from 28 July.
How many people Origin has not confirmed a figure. The claimant said around two million records; subsequent reporting has put the confirmed number closer to 900,000 current and former customers.
Type of incident Data theft. No reports of encryption, destruction or service disruption — the lights stayed on and the bills kept arriving.
Investigating Australian Cyber Security Centre, National Office of Cyber Security, Australian Federal Police, and the Office of the Australian Information Commissioner.
Unusual element The claimant went to the media directly and was later reported to have agreed not to leak the data following some arrangement with Origin, which Origin has not confirmed. The person’s identity and affiliation remain unverified.
“It won’t be leaked” should change nothing about your planning

Nobody can verify that a copy does not exist, has not already been passed on, or will not surface in two years. Data that has left an organisation should be treated as permanently in circulation. Plan for the fraud attempts, not for the reassurance.

Four Digits That Change Everything

Australia has been through Optus, Medibank, Qantas and a long list of smaller incidents, and there is a real risk of breach fatigue — another announcement, another apology, another year of free credit monitoring. This one is worth a second look for one specific reason.

The last four digits of a card cannot be used to make a payment. What they can do is prove identity — or appear to. They are the exact detail a bank reads back to you so that you know the call is genuine.

“Good morning, it’s the fraud team — we’ve blocked a transaction on the card ending 4417, is that yours?” The entire verification habit Australians have been taught rests on the assumption that only the real organisation knows that number. Once a criminal knows it, the ritual designed to protect people becomes the mechanism that convinces them.

Layer on a full name, a home address and a date of birth and the caller can satisfy most casual identity checks. There is no realistic way for the person answering to distinguish that call from the real thing by listening harder. That is why generic advice to “stay vigilant” is close to useless here, and why the defence has to be a process rather than an intuition.

AI Removed the Effort Barrier

For twenty years, ordinary people were protected less by their own skill than by the attacker’s workload. Analysing a stolen dataset and writing individually convincing approaches took real hours, so the economics pushed criminals towards generic, misspelt bulk messages that most recipients could spot.

That barrier has gone. A model can read two million records in minutes, segment by postcode to find wealthier suburbs, cross-reference names against public social media, and generate fluent, individually tailored approaches at any scale you like.

Minutes
To profile and segment a dataset that once took weeks of manual work
0
Spelling mistakes — the heuristic Australians were trained on no longer applies
Seconds
Of audio needed to clone a recognisable voice for a phone call
$4bn+
Industry estimate of fraudulent mortgage applications across the major banks, many using AI-generated documents

Australian banks have publicly described a flood of fraudulent home loan applications supported by AI-generated payslips and statements convincing enough to pass initial review. If that standard of forgery is reaching bank credit teams, assume it is reaching your accounts payable clerk. The voice dimension is covered separately in AI voice cloning and vishing.

Six Approaches Your Team Will See

The breach is an event. The fraud is the consequence, and it typically arrives weeks or months later once the data has been sorted and traded.

🏦

1. The bank fraud call

Opens with a real partial card number. Wants a one-time code, banking credentials, or a transfer to a “safe account”. The most convincing of the lot.

🧾

2. The supplier bank-detail change

An email or call saying a supplier’s account has changed. One redirected payment, often large. Consistently the costliest attack on Australian small business.

👔

3. The director impersonation

A voice message or call that sounds like the boss, urgently needing a payment made or cards purchased. Exploits hierarchy and time pressure together.

💻

4. The IT help desk

“We’re rolling out new MFA, read me the code that just arrived.” Account takeover, and then everything that account can reach.

📲

5. The utility bill SMS

An overdue notice or a refund, with a link to a payment page indistinguishable from the real one. Especially effective when it threads into legitimate messages.

🕰️

6. The slow build

Several harmless contacts over weeks to establish familiarity, then the request. Patient, tailored, and how the largest losses actually happen.

Make Your Phone System Part of the Defence

Registered sender IDs, call recording on finance lines, AI screening of unknown callers, and a platform we own, operate and host in Australia — with Australian people answering when you need them. Let’s look at where your phone is currently the soft spot.

Talk to Us Or call 1300 663 222

Why It Lands on You Regardless

It is easy to read a breach at an energy retailer as somebody else’s incident. Four reasons it is not.

ReasonWhat it means concretely
Your people are in the data Millions of Australian households buy energy from Origin. Statistically several of your staff are in that dataset with their home address, date of birth and mobile number — the raw material for approaches that reach them at work.
Breaches merge Criminals combine datasets. Origin plus Optus plus Medibank plus a decade of smaller leaks produces a profile far richer than any one incident, and none of it expires.
Your brand is borrowable Whatever you sell, someone can ring your customers pretending to be you. You carry the reputational damage from a fraud you did not commit and could not see.
Home details still unlock work accounts Date of birth and address remain accepted as identity verification at far too many help desks. Possibly including yours.

Where Australian Law Sits in 2026

FrameworkYour obligation or opportunity
Notifiable Data Breaches scheme If you are covered by the Privacy Act and suffer an eligible breach likely to cause serious harm, you must assess promptly and notify affected individuals and the OAIC.
Privacy Act reform Penalties for serious or repeated interference with privacy have risen sharply, and a statutory tort for serious invasions of privacy now exists. A breach is a financial event, not only a reputational one.
Scams Prevention Framework Legislated in February 2025, placing prevent, detect, disrupt and report duties on banks, telcos and digital platforms, with sector codes following. See the telco transparency and consumer protection rules.
SMS Sender ID Register Registering your sender ID prevents criminals sending messages that appear inside your genuine SMS thread with a customer — the detail that makes those texts work. See the Sender ID Register guide.

Phone-Side Controls That Actually Help

Email has had two decades of security investment — filtering, sandboxing, external-sender banners. The telephone has had almost none, which is exactly why capable attackers have moved to it. A call carries urgency and a human voice, and leaves no artefact for anyone to inspect afterwards unless you deliberately create one.

ControlWhat it changes
Recording on finance and service lines Creates the artefact. When a payment is questioned three weeks later, there is a conversation to review rather than two conflicting recollections.
AI screening of unknown numbers An AI agent answers unrecognised callers, establishes who they are and what they want, and hands your team a summary — so nobody is improvising cold against a professional.
Registered SMS sender ID Stops a scam text threading into your legitimate conversation with a customer, which is the single thing that makes those messages credible.
Separate published numbers per function Accounts, support and sales on their own lines gives customers a stable, verifiable contact point and makes unusual patterns visible in your reporting.
An explicit callback invitation Say it in your greeting, on invoices and in email footers: hang up and ring our published number if you are unsure. Normalising verification is what makes people do it.
Australian-hosted platform, Australian support Recordings and call metadata are sensitive. Know which jurisdiction holds them and who you can actually reach during an incident — see who owns the network your calls run on.

The Ninety-Second Rule

Never verify an inbound call using information the caller gave you

If someone rings claiming to be your bank, a supplier, a government agency or your IT provider: end the call and ring back on a number you already had. From an invoice in your files. From your own records. From the website you navigated to yourself. Not the number they read out, not the number in the email that prompted the call, and not the number that appeared on your screen — caller ID is trivially spoofed and should be treated as decoration.

The reason this rule is so powerful is that it does not require anyone to detect anything. It does not matter how fluent the caller was, how much they knew, or whether the voice sounded like your finance director. The verification happens over a channel the attacker does not control, so their entire performance is irrelevant.

It costs about ninety seconds. Make it a written policy, apply it to payments and credential requests without exception, and remove urgency and seniority as grounds for skipping it — because urgency and seniority are the two levers every one of these attacks pulls.

What to Do This Week

#ActionEffort
1 Multi-factor authentication on email, banking, accounting and phone system administration. Prefer an authenticator app or hardware key over SMS codes. An afternoon, and still the highest-value control available.
2 Write the callback rule for payments and bank-detail changes. No exceptions for urgency or seniority. Tell the team it applies to the directors too. An hour. Defeats the two most expensive attacks outright.
3 Register your SMS sender ID. An hour, and it protects your customers rather than you — which is the point.
4 Unique passwords in a password manager, everywhere, no exceptions. A week to roll out. Reuse is what turns one breach into ten.
5 Publish how you will and will not contact people: “we will never ring and ask for a code”, on invoices, footers and your contact page. Thirty minutes. Gives customers a rule they can apply without judging a voice.
6 Delete data you no longer need and stop collecting what you cannot justify. Ongoing. The cheapest data to protect is the data you never held.
7 Rehearse a breach response: who decides, who notifies, who answers the phones. Half a day, once. Doing it for the first time on the day goes badly.

And one cultural change that outperforms all seven. Tell your team, in writing and out loud, that they will never be criticised for verifying — not for making a caller wait, not for ringing a director back through another channel, not for holding an urgent payment until tomorrow. Then mean it. The first time somebody is made to feel foolish for checking, the policy is gone and every control above it is decorative.

If the Breach Is Yours

Origin’s response is happening in public, which makes it a useful rehearsal for everyone else.

Fast beats polished

A partial honest update on day one earns more trust than a perfect statement on day nine, because the silence in between gets filled by the attacker’s version.

📋

Be specific about what went

People can only protect themselves if they know which details are out. Vagueness reads as concealment and makes the follow-on fraud more effective.

📞

Plan for the call spike

Everyone rings at once. Callback queues, overflow, an AI agent handling the repeated questions and clear IVR messaging are the difference between coping and drowning.

🛑

Do not ring customers for verification

Post-breach outbound calls asking people to confirm identity details train your own customers to behave exactly as the criminals need them to.

The call-volume point deserves advance planning rather than improvisation. A notification sent to tens of thousands of customers produces a spike no ordinary team absorbs, and a cloud platform can add queue capacity and overflow paths in minutes — but only if somebody has thought about it before the day arrives.

The Origin story will leave the news long before its consequences do. Stolen dates of birth and addresses cannot be rotated like a password; they will be in use for years. The businesses that come through it well will not be the ones that followed the coverage most closely. They will be the ones that spent a week in August 2026 switching on MFA, writing a callback rule, registering a sender ID, and telling their people that checking is always welcome.

Frequently Asked Questions

What did the Origin Energy breach expose?
Origin Energy confirmed in late July 2026 that customer data had been accessed, and said the information may include name, address, date of birth, contact phone number and account information, along with the last four digits of a credit card or the last three digits of a bank account. The incident surfaced when the person claiming responsibility approached The Australian newspaper with sample data and screenshots said to be from internal systems, saying he had records for around two million customers. Origin has approximately 4.8 million customers and has not itself confirmed the number affected, while subsequent reporting has put the figure closer to 900,000 current and former customers. It was flagged internally in early July, assessed as credible around 22 July and publicly confirmed from 28 July. The Australian Cyber Security Centre, National Office of Cyber Security, Australian Federal Police and the Office of the Australian Information Commissioner are all involved, and no destruction or service disruption has been reported - this was data theft.
Why do the last four digits of a card matter so much?
Because they cannot be used to make a payment but they can be used to prove identity, and that asymmetry is the whole problem. Reading back the last four digits is exactly what a genuine bank does so that you know the call is real. When a criminal has them, the ritual designed to protect people becomes the thing that convinces them. Add a full name, home address and date of birth and the caller passes most casual identity checks, and the person answering has no way to tell the difference by listening more carefully. This is why advice to stay vigilant is so weak in this situation. Vigilance assumes there is something detectable, and with a fluent caller who already knows real details about you there frequently is not. The defence has to be procedural rather than perceptual: never verify an inbound call using information the caller supplied, and always ring back on a number you already held.
Has AI made data breaches more dangerous?
It has made the aftermath far more dangerous, which amounts to the same thing. Historically people were protected less by their own skill than by the attacker's workload - analysing stolen records and writing individually convincing approaches took real time, so the economics pushed criminals towards generic bulk messages that most recipients could recognise. Generative AI removed that constraint. A model can read millions of records in minutes, segment by postcode to identify wealthier areas, cross-reference names against public social media, and produce fluent tailored approaches at unlimited scale. The classic warning signs - poor grammar, odd phrasing, generic greetings - are no longer reliable. AI also produces convincing fake documents, and Australian banks have reported a wave of fraudulent home loan applications supported by AI-generated payslips, with industry estimates putting fraudulent mortgage value across the major banks in the billions. If that quality of forgery reaches bank credit teams, it will reach your accounts payable.
What is the single most effective thing we can do?
Adopt and enforce a callback rule: any request involving a payment, a change of bank details, or credentials is verified by ending the call and ringing back on a number you already had - from an invoice in your files, your own records, or a website you navigated to yourself. Never the number the caller provides, never the number in the triggering email, and never the number displayed on your screen, because caller ID is trivially spoofed. This works precisely because it removes the need to detect anything. It does not matter how convincing the caller was or how much genuine information they knew, since verification happens over a channel they do not control. The rule must apply without exception for urgency or seniority, because urgency and seniority are the two levers every one of these attacks pulls. Write it down, apply it to directors as well as juniors, and make clear that nobody will ever be criticised for using it.
What are our obligations if our own business suffers a breach?
If you are covered by the Privacy Act, the Notifiable Data Breaches scheme requires you to assess a suspected breach promptly and, where it is likely to result in serious harm, notify both the affected individuals and the Office of the Australian Information Commissioner. Privacy Act reform has substantially increased penalties for serious or repeated interference with privacy and introduced a statutory tort for serious invasions of privacy, so the exposure is financial as well as reputational. Beyond compliance, the practical response matters: move fast rather than waiting for a polished statement, be specific about what data was taken so people can actually protect themselves, and plan for the phone volume, because notifying thousands of customers produces a call spike an ordinary team cannot absorb. One thing to avoid absolutely is making outbound calls asking customers to verify identity details afterwards, because that conditions them to do exactly what the criminals will ask next.
How can a phone system help rather than being the weak point?
Email security has had two decades of investment while the telephone has had almost none, which is precisely why capable attackers moved to voice. Several controls close that gap. Recording on finance and service lines creates an artefact, so a disputed payment three weeks later has a conversation to review instead of two conflicting memories. AI screening of unknown numbers means an agent establishes who is calling and why before a human picks up, so nobody improvises cold against a professional. A registered SMS sender ID stops scam texts threading into your genuine messages to customers. Separate published numbers for accounts, support and sales give people a stable verifiable contact point. An explicit invitation to hang up and call back, stated in your greeting and on invoices, normalises the behaviour that actually protects people. And knowing which country holds your recordings and metadata, with a support team you can reach during an incident, matters more than it seems until the day it matters a lot.
Should we warn our customers, and what should we say?
Yes, and the most useful message is not about the Origin breach specifically - it is a standing statement about how you will and will not contact people. Something short and concrete: we will never ring you and ask for a one-time code, we will never ask you to move money to a safe account, our bank details do not change, and if you are ever unsure please hang up and call our published number. Put it on invoices, in email footers, on your contact page and in your on-hold message, and repeat it rather than saying it once. This works because it gives customers a rule they can apply mechanically instead of requiring them to judge how convincing a caller sounds, and judging convincingness is exactly what people are now unable to do reliably. Pair it with a genuinely easy callback path, and make sure your own team never asks customers for anything the statement says you would not.

What to Read Next

Your next reads

VOCPhone logo

VOCPhone — the Australian-owned cloud phone platform that owns and operates its own network. vocphone.com | 1300 663 222

Related Articles