Origin Hack traced to Accenture’s Manila office

SYDNEY, AUSTRALIA — Australian authorities have traced a data breach affecting approximately 900,000 Origin Energy customers to a former employee at Accenture’s Manila call center, where the individual worked on outsourced billing and customer support before allegedly using stolen data to attempt to extort the energy company.
Origin first learned of the potential threat in early July 2026 when it was deemed not credible. A hacker then sent 50 sample customer records to The Australian on July 23, and Origin confirmed approximately 900,000 affected customers five days later as reported by Australian Financial Review.
Billing and personal data for 900,000 customers exposed
Accenture operates call centers in Manila handling business process outsourcing (BPO) work for Origin Energy, including billing and customer support functions that gave the former employee direct access to customer records.
The breach exposed names, addresses, email addresses, dates of birth, phone numbers, and billing histories belonging to approximately 900,000 current and former Origin customers, according to Origin Energy.
“To our customers, I am sorry. We don’t take for granted the trust customers place in Origin and our safeguarding of their information,” said Frank Calabria, CEO at Origin Energy.
AFP investigates; Accenture declines to comment on criminal probe
The Australian Federal Police (AFP) confirmed it is investigating the breach and working closely with Origin Energy and relevant partners to gather evidence and identify those responsible.
The former Accenture employee, not publicly identified, allegedly sought payment from Origin in exchange for returning the stolen data rather than publishing or selling it.
Accenture declined to comment, stating it was not appropriate to do so while the incident remained under active criminal investigation.
“AFP investigators are focused on gathering evidence, identifying those responsible, and disrupting any associated criminal activity,” an Australian Federal Police spokesperson said.
For buyers evaluating outsourcing partners in the Philippines, the case illustrates the insider threat dimension of third-party data risk: a former BPO employee exploiting data access accumulated during a client engagement.
The breach is structurally similar to the 2025 vishing attack on Qantas’ Manila-based call center, which exposed data belonging to six million flyers, and reinforces data access controls and offboarding procedures at BPO partners as due-diligence items equal in weight to service-level agreements.
The AFP investigation is ongoing and no charges were confirmed at the time of reporting.
Related news
- Qantas call center breach affecting 6 million flyers · Jul 2025
- Philippines’ $40Bn IT-BPM sector at risk as cyberattacks threaten trust · Jul 2025
Disclosure: Outsource Accelerator uses AI tools in the backend of its editorial workflow. Every article is reviewed and verified by a human editor before publication.
Stay ahead of the outsourcing industry. Join thousands of business leaders who rely on Outsource Accelerator for the news, trends, and expert insights that matter. Subscribe to our free newsletter and never miss an update.

Independent




