Nearly a Million Australians' Data Stolen in Origin Energy Breach Traced to Manila Call Centre

A former employee at a Manila-based Accenture office allegedly took customer records belonging to roughly 900,000 Origin Energy customers and tried to extort the company for money to return them.

ThreatVectr Newsdesk· 3 min read
Macro photograph of a smart ring resting on a dark matte surface beside a dimly lit laptop keyboard, cool blue ambient light casting subtle shadows, sharp focus
Share

Key points

  • Roughly 900,000 current and former Origin Energy customers had personal data accessed in a breach discovered in early July 2026.
  • Australian Federal Police confirmed they are actively investigating and gathering evidence.
  • A former Accenture employee in Manila, Philippines, is linked to the breach, according to a Nine report confirmed to ABC News Australia by Accenture.
  • The stolen data includes names, home addresses, email addresses, dates of birth, phone numbers, and billing histories.
  • Origin Energy initially did not believe the threat was credible when it first emerged.

Something went wrong inside a call centre in Manila, and nearly a million Australians are now waiting to find out exactly what.

Authorities have traced a data theft at Origin Energy, one of Australia's largest electricity and gas retailers, to a former employee at Accenture's Philippines office. Accenture, the global consulting firm, runs call centre operations on Origin's behalf. The individual allegedly took a large volume of customer records and then tried to extort Origin for money in exchange for returning that data.

Accenture confirmed the broad details to ABC News Australia but said it would not be commenting further. Origin Energy also declined to comment, citing an active criminal investigation.

What information was taken?

The stolen records cover approximately 900,000 current and former Origin customers. Each record could include a customer's full name, home address, email address, date of birth, phone number, and billing history.

That combination is exactly what criminals need to impersonate someone. A fraudster with your name, address, date of birth, and contact details can open accounts, apply for credit, or craft highly convincing scam calls pretending to be your bank or energy provider.

Origin says it became aware of a potential security threat in early July 2026 but initially did not consider it credible. The company later alerted authorities after a hacker sent a sample of 50 customer records to a news outlet, which first reported the breach.

What should Origin customers do right now?

Origin is offering specialist identity and cyber support services to affected customers. Take them up on it.

Beyond that, four practical steps:

  • Watch for unusual bills, credit applications, or accounts you did not open.
  • Be sceptical of any phone call or email claiming to be from Origin, your bank, or a government agency asking you to confirm personal details.
  • Consider placing a credit alert with Australia's credit reporting agencies so lenders have to verify your identity before issuing credit in your name.
  • Change your Origin account password and any other account where you used the same password.

How does this fit the bigger picture?

This is the insider-threat pattern that attribution analysts often note is harder to detect than external hacking. There was no need to break through firewalls, which are the digital barriers companies use to keep outsiders out. The person allegedly responsible already had legitimate access to customer data as part of their job.

Origin CEO Frank Calabria apologised publicly in July: "We don't take for granted the trust customers place in Origin and our safeguarding of their information."

The Australian Federal Police said it is "working closely with Origin Energy and relevant partners" and that Origin "has been cooperative and transparent."

Australia has seen a string of large breaches in recent years. Qantas was hit in 2025; Optus and Medibank both suffered mass breaches in 2022. The pattern suggests that organisations sharing customer data with third-party service providers need tighter controls over who can access that data, and closer monitoring of when it is downloaded in bulk.

© 2026 Threat Vectr