Origin Energy breach traced to former Accenture Manila employee

Nearly 900,000 current and former Origin Energy customers had personal data compromised, creating identity theft and fraud risks.
We don't take for granted the trust customers place in Origin
Origin's CEO apologized after the breach exposed nearly 900,000 customers' personal data to a former offshore employee.
Mark

Why does it matter that the breach was traced to someone in Manila rather than, say, someone in Sydney?

Mimi

Because it raises a question about where companies choose to store and handle their most sensitive customer information. Accenture runs call centres there for cost reasons, but that decision creates distance—physical, legal, jurisdictional—between the company and the data. When something goes wrong, the response is slower, the accountability murkier.

Mark

The employee wanted extortion money. That's a different kind of crime than just selling data on the dark web.

Mimi

It is. It suggests someone with access who understood what they had and thought they could negotiate directly with the company. That's a person who knew they had leverage. It's also riskier for them, which might explain why they were caught.

Mark

Origin didn't initially believe the threat was credible. What does that say?

Mimi

It says that companies receive threats constantly, and they've learned to be skeptical. But it also means that when a real threat arrives, there's a delay before anyone acts. By the time Origin took it seriously, the damage was already done.

Mark

Nearly a million people. That's a staggering number.

Mimi

It is. And most of them will never know exactly how their data was used or whether it's still at risk. They'll just have to be vigilant, watch their credit reports, and hope nothing happens. That's the real cost—not to Origin, but to the people whose trust was broken.

Mark

Will this change how companies use offshore call centres?

Mimi

Probably not immediately. The cost savings are too significant. But it might push some companies to invest more in security at those locations, or to limit what data those centres can access. Whether that actually happens is another question.

  • A former Accenture employee in Manila allegedly stole personal records from roughly 900,000 Origin Energy customers and demanded payment for their return — turning a routine call centre role into an extortion operation.
  • Sample data sent to a major newspaper forced the breach into public view, stripping Origin of any quiet resolution and triggering an Australian Federal Police investigation.
  • Affected customers — armed with little more than vague corporate statements — now face real exposure to identity theft and fraud, with anxiety running high and trust in the energy provider badly damaged.
  • Origin has pointed customers toward identity support services and urged vigilance against scams, while AFP works to disrupt further criminal activity and gather evidence against those responsible.
  • The incident lands in a country already raw from the Optus and Medibank breaches of 2022 and the Qantas hack of 2025, raising urgent questions about whether Australian corporations have genuinely hardened their offshore security practices or merely apologised and moved on.

In the long and troubled story of digital trust, Australia has again found itself at a familiar crossroads: nearly a million Origin Energy customers learned in mid-2026 that their personal details — names, birthdays, billing histories — had passed into unknown hands, traced to a former Accenture employee at a Manila call centre who allegedly sought ransom for their return. The breach is not merely a corporate failure but a quiet reckoning with the hidden costs of globalised infrastructure, where the convenience of offshore operations carries risks that customers never consented to bear. As Australian Federal Police pursue the investigation, the incident joins a growing ledger of mass data exposures that have come to define the country's digital decade.

In early July, Origin Energy detected signs of a potential security threat but initially doubted its severity. By late July, that doubt had collapsed: investigators had traced a major data breach affecting roughly 900,000 current and former customers to a former Accenture employee working at the company's Manila call centre.

The breach first surfaced publicly when a hacker sent fifty sample customer records — names, addresses, emails, dates of birth, phone numbers, and billing histories — to The Australian newspaper. Origin alerted authorities, and the Australian Federal Police opened an investigation. Accenture, which operates offshore call centre services for Origin in the Philippines, confirmed the investigation but offered little further comment. Origin similarly stayed quiet, citing the active criminal inquiry. Reporting by Nine revealed the alleged motive: the former employee wanted money in exchange for returning the stolen data.

For the nearly one million people affected, the breach was not an abstraction. Their most sensitive personal information — the kind used to open accounts, verify identity, and commit fraud — was now in unknown hands. Customers told the ABC they felt anxious and frustrated, particularly by the lack of clear communication from Origin about what had actually happened. The company eventually urged vigilance against scams and made identity and cyber support services available, but the damage to trust had already set in.

Origin chief executive Frank Calabria issued a public apology in July, acknowledging the breach and the responsibility the company holds for customer data. It was a measured statement, but for those whose information had been exposed, it offered limited comfort.

The incident arrives in a country that has lived through this before. Optus and Medibank both suffered mass breaches in 2022. Qantas followed in 2025. Each time, millions of Australians were left vulnerable; each time, corporations apologised and pledged improvement. The Origin breach raises a harder question: whether those pledges have translated into meaningful change, or whether the pattern is simply repeating itself with new names attached.

In early July, Origin Energy noticed something wrong. A potential security threat had surfaced, but the company didn't immediately treat it as credible. By late July, that assessment had changed. Investigators had traced a major cyber breach—one that would eventually expose the personal details of roughly 900,000 current and former customers—back to a former employee of Accenture working at a call centre in Manila.

The breach itself had been flagged weeks earlier when a hacker sent sample data to The Australian: fifty customer records containing names, addresses, email addresses, dates of birth, phone numbers, and billing histories. That was enough to trigger an alert. Origin contacted authorities, and the Australian Federal Police began their work.

Accenture, a multinational consulting and technology services firm, operates offshore call centres for Origin Energy in the Philippines. The company confirmed details of the investigation to the ABC but declined to elaborate further. Origin Energy, similarly, offered little public comment, citing the ongoing criminal investigation. What emerged from reporting by Nine was the alleged motive: the former employee wanted money in exchange for returning the stolen information. It was extortion dressed in the language of data theft.

For the customers affected, the breach represented a tangible threat. Nearly a million people suddenly had to reckon with the possibility that their most sensitive personal information—the kind used to open accounts, verify identity, commit fraud—was now in unknown hands. Origin customers told the ABC they felt anxious about what had happened and frustrated that the company hadn't given them clear, detailed information about the scope and nature of the incident. The energy provider did eventually urge customers to stay alert for scams and made specialist identity and cyber support services available, but the damage to trust had already been done.

Origin's chief executive Frank Calabria issued a statement in July acknowledging the breach and apologizing to customers. "We don't take for granted the trust customers place in Origin and our safeguarding of their information," he said. It was the kind of statement companies issue after these incidents—measured, contrite, and ultimately insufficient for people whose personal data was now exposed.

The breach was not an isolated incident. Australia had seen this pattern before. Qantas suffered a major hack in 2025. Optus and Medibank both experienced mass breaches in 2022. Each time, hundreds of thousands or millions of Australians found themselves vulnerable. Each time, companies apologized and promised to do better. The Origin breach suggested that the lessons, if learned at all, had not been fully absorbed across the corporate sector.

The Australian Federal Police told the ABC they were working closely with Origin and other partners to gather evidence and identify those responsible. An AFP spokesperson said investigators were focused on disrupting any associated criminal activity. Origin, the police noted, had been cooperative and transparent throughout the process. The investigation continued, but for the 900,000 people whose data had been compromised, the waiting had already begun.

We don't take for granted the trust customers place in Origin and our safeguarding of their information.
— Frank Calabria, Origin Energy CEO
AFP investigators are focused on gathering evidence, identifying those responsible, and disrupting any associated criminal activity.
— Australian Federal Police spokesperson
Nous contacter FAQ