Customer personal information — names, addresses and partial payment method data — was leaked at Origin Energy, an Australian energy retailer with a customer base of around 4.8 million. The affected population has not been disclosed.
We are careful with the 4.8 million figure. It describes the company’s customer base, not the number of people affected, and reporting that conflates the two is how a company-size statistic becomes a breach headline.
Energy Accounts Accumulate
An energy account typically runs for as long as someone occupies a property, and the record persists after they leave — for billing reconciliation, debt recovery and regulatory retention. A retailer therefore holds address histories rather than addresses.
An address history is a more useful artefact than a current address. It supports identity verification questions, and it describes where a person has lived over time, which is not information most people consider themselves to have given anyone.
Partial Payment Data Is Not Nothing
Partial card data is reported reassuringly, and it does prevent direct card-not-present fraud. It also supplies exactly the fragments used to make a fraudulent call convincing — the last four digits, the card type, the billing address.
That is the raw material for the vishing campaigns that dominate this database. Graded low: the incident is reported, the affected population is not disclosed, and the access route is not established.
Compiled from public reporting, listed below. The 4.8 million figure is the company’s customer base, not an affected count, and is labelled as such. Corrections: corrections@forensicpost.com.
- Data breach roundup (July 17–23, 2026)Privacy Guides