The Sydney-based company said on Thursday it was working to understand how many of its almost five million customers were affected by the privacy incursion.
Names, addresses, dates of birth, phone numbers and account information could all have been viewed in the breach, Origin said in an ASX statement.
Also at risk were the last four digits of credit cards, or the last three digits of bank accounts.
Origin chief executive Frank Calabria apologised to customers and said the company was working to contact those affected.
The company has set up a contact number and "additional resources to help manage our response to this incident".
"One of our key priorities is taking action to secure our systems and ensure no further unauthorised access," Mr Calabria said.
"We are working with independent cyber experts to support Origin, and that work is continuing alongside the work of authorities."
The company continued to engage with federal cyber and information agencies on the incident as well as police, according to the statement.
Origin, which has 4.8 million customer accounts in Australia and provides electricity, natural gas, LPG and internet services, said on Wednesday it did not believe the data obtained included credit card or bank details.
Griffith University's Graeme Hughes, an expert on business and consumer issues, said the breach was unlikely to cause cases of payment fraud but marked a "social engineering problem".
"The last four digits for a card, a date of birth, and an authentic billing history are the exact trust signals a businesses uses to verify itself over the phone," Professor Hughes told AAP.
"That makes an unsolicited call about an energy account far more convincing than it should be.
"If comparable Australian breaches have taught us anything, the confirmed scope (of the breach) usually widens rather than narrows."
The breach represents the country's most high-profile cyber incident since Partnered Health, owned by private equity firm Quadrant, said earlier in July that its medical records were breached clinics in Sydney, Melbourne and Canberra.
In 2025, airline Qantas said it had customer data published by cybercriminals, while telco giant Optus and health insurer Medibank were hit in attacks in 2022 that sparked cyber-resilience laws.