Origin Energy released its initial forensic scoping findings confirming that approximately 900,000 current and former customers had personal details exposed in the July security incident. Compromised data fields include full names, residential addresses, dates of birth, phone numbers, and utility account identifiers. Partial financial identifiers were also exfiltrated for a subset of users (including the last four digits of credit cards and last three digits of bank account numbers). Origin confirmed it first identified anomalous threat telemetry in early July but verified true system intrusion on July 22, initiating active victim notification workflows alongside the ACSC and OAIC.