Company confirms full bank account numbers accessed for 60 customers, while executive bonuses are reduced following the incident.
AI-generated summary
Origin Energy experienced a major cybersecurity breach in July affecting approximately 900,000 customers. The incident has been linked to a former Accenture employee in Manila.
Origin Energy says as many as 60 customers had their full bank account numbers accessed by a hacker in July.
Last month, Origin confirmed a major cybersecurity breach affecting approximately 900,000 current and former customers.
The company has also updated the public, saying that for those 900,000 customers affected by the July security breach, information accessed included some combination of name, address, date of birth, contact phone number, account and other information about the customers' personal circumstances, as well as the last four digits of a credit card, or the last three digits of a bank account.
The hacker, Origin has confirmed, also accessed "numbers associated with government concession scheme or program, affecting approximately 15,000 customers in total".
In addition, approximately 100 customers have had an "ID document number" accessed, stressing it was "the number only, no scanned copies of ID documents were affected".
"We have now confirmed the specific types of information that have been accessed on a customer-by-customer basis, and are well advanced in providing further specific notifications to each affected customer," the company said in a statement.
"Those specific customer notifications include details of the information that has been accessed, advice on the practical steps they can take and the various supports available."
The criminal investigation into the breach is still ongoing, Origin Energy CEO Frank Calabria said.
"We have substantially completed our review into the information accessed for each affected customer, and our priority is completing our notifications to them and providing support," he said in a statement.
He added that the company is working closely with the federal government, the Australian Cyber Security Centre, the National Office of Cyber Security and the Australian Federal Police.
The update from the energy company comes after authorities traced the cyber hack to a call centre in the Philippines, with the investigation linking the breach to a former Accenture employee in Manila.
Accenture works with Origin to run its call centres, but a spokesperson for the company declined to comment on the Origin incident when contacted by the ABC on Tuesday.
Putting 'legal defence' before customers
On Friday, Origin Energy confirmed to the ABC that the alleged hacker had not leaked or disclosed any customer data to the public.
Despite this, Origin has provided several support options for affected customers, including identity monitoring and 12 months of free credit monitoring.
The company has also recommended customers be cautious of any unusual or suspicious activity, particularly in communications that appear to come from Origin, the government, or their bank.
Cyber security expert Troy Hunt criticised the latest update from Origin on Friday, saying it and other large corporations are taking too long to inform and update customers potentially affected by a hack.
"[Origin is] saying a lot [in this latest announcement] without saying much," he told the ABC.
"Organisations are saying less and less, which is a shame.
"I would have liked to have understood a little more about the hack."
Mr Hunt believes large publicly-listed organisations too often prioritise information management over customer needs.
"Within these organisations there is a big component of trying to preserve shareholders' value," Mr Hunt said.
"Their primary accountability is not shareholders, not customers."
Executive bonuses slashed after breach
In its latest annual report published last Thursday, Origin Energy confirmed its executive managers would have their bonuses reduced as a result of the data breach.
It noted the board determined docking bonus pay would appropriately reflect "shared accountability and to recognise the large number of customers involved and the importance of the security of our systems and customer data".
That saw CEO Frank Calabria's pay reduced by $357,000, and other executive management reduced by $607,000.
But the board said it would consider future financial penalties against executives once all reviews and investigations had been completed.
It was the only financial mention of the data breach in its results, with the company noting it would be included in its results for the 2027 financial year instead.
The breach was first reported by The Australian in July, when the alleged hacker sent a sample of 50 customer records containing names, addresses, emails, dates of birth, phone numbers and billing histories.
Only after The Australian sent that information to Origin Energy did the company alert authorities to a potential security breach.
The data breach is believed to be the largest known incident experienced by an Australian energy retailer. A cyber incident in September 2022 resulted in details of hundreds of EnergyAustralia customers being exposed.
Origin Energy customers had reported delays in receiving their energy bills in the days before the data breach was confirmed. However, the company said it was not connected to the incident.
Origin is one of several major Australian companies to experience a security breach, after Qantas suffered a major hack in 2025 and Optus and Medibank experienced breaches in 2022.
On Wednesday, Quest Apartment Hotels became the latest business to experience a security breach that affected customers' data.

Melbourne developer House House, creators of Untitled Goose Game, discusses their new title Big Walk. The game, which emphasizes proximity voice chat and collaborative puzzle-solving, has achieved over 1 million downloads in its first week.
Australia's world-first teen social media ban, in effect for eight months, shows minimal visible change in teen social media usage, with 81.5% of teens still using social media, down from 85.9% pre-ban. The ban's porous design and reliance on tech companies for enforcement have been criticized, prompting questions about its effectiveness and the potential for alternative approaches like a digital duty of care.
Telstra network upgrades in Gnowangerup, Western Australia, causing week-long outages have raised concerns among emergency responders and local businesses over communication gaps and crippled eftpos systems.
Darwin residents and local councillors have called for a moratorium on proposed data centres in the Northern Territory, citing intense water consumption, noise, and reliance on gas-powered energy.
South Australia announces a royal commission into artificial intelligence to set policy frameworks and examine AI impacts on work, education, and public services, set to begin October 1.

An Indonesian woman named Adira and other overseas creators are running prolific Facebook accounts targeting Australian and US politics to earn money through Meta's creator monetization program.