Executive Summary On 28 July 2026, Origin Energy publicly confirmed a significant data breach affecting approximately 900,000 current and former customers. The breach resulted in unauthorized access and exfiltration of personally identifiable information (PII), including names, addresses, dates of birth, phone numbers, account details, and partial payment information such as the last four digits of credit cards or the BSB and last three digits of bank accounts. The incident was first identified as a potential threat in early July 2026, but only confirmed as a credible security incident on 22 July 2026, with public disclosure and customer notification following shortly thereafter. The breach is currently under investigation by Australian authorities, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police, and the Office of the Australian Information Commissioner. No technical indicators of compromise (IOCs) have been published as of the date of this report. All facts in this summary are corroborated by the official Origin Energy disclosure (Origin Energy, 28 July 2026), ABC News (ABC News, 28 July 2026), and Nine.com.au (Nine.com.au, 28 July 2026). Technical Information The Origin Energy data breach represents a major compromise of customer data within the Australian energy sector, a critical infrastructure domain. The breach involved unauthorized access to systems containing sensitive customer information. The types of data confirmed as compromised include names, addresses, dates of birth, phone numbers, account information, and partial payment details (last four digits of credit cards or the BSB and last three digits of bank accounts) (Origin Energy, 28 July 2026; Nine.com.au, 28 July 2026). Attack Vector Analysis The specific technical vector used to gain initial access remains undisclosed. Origin Energy began reviewing a "potential security threat" in early July 2026, which was initially not deemed credible (Origin Energy, 28 July 2026; ABC News,