Origin cyber attack, hugely embarrassing and poorly managed

July 23, 2026

Utilities and telcos are prime targets of cyber attack.  The number of unsuccessful attacks are rarely publicised.  The successful attacks which involve access to large amounts of data are well publicised.  As the recent attack on Origin energy proves.  Not surprising given the hacker claims to have accessed records of 2 million customers.  It has been reported by the ABCNineNews.com, cyber daily and others.  Origin has sort of confirmed there was a data breach and has released a wholly inadequate statement which it describes as a potential customer data breach.  A dreadful approach.  Saying less than very little and leaving customers wondering. if not anxious, about what happened to their personal information.  Its attempt at minimising concern is to say that it didn’t believe bank records or credit card details were stolen.  Even then it was very qualified.  Even if it did not know the full scope of the data breach it could have provided a better response.  There is now a skill on how to respond.  Which Origin does not possess.

What is very disappointing, more than its non statement statement, is that Origin Energy was made aware of the cyber attack almost three weeks ago.  By the hacker.  And to make matters worse the hacker contacted the Australian 2 days ago.  Origin gave the impression then that no data had been stolen.  So the next day the hacker provided a sample of 50 customer records to the Australian.  The immediate reaction from Origin was dreadful.  The fact that Origin contacted the ASX after being notified by the media bespeaks a serious problem with Origin’s data breach response plan.  If such a plan existed.  If it existed then the likely explanation was that Origin adopted a low profile and hoped it would all go away.  An attitude some companies still take and a product of long standing poor regulation in the past and even worse enforcement until recently. The situation got worse for Origin today when the hacker told the Australian that Origin sacked an employee after accusing him or her of being behind the data breach (even though the hacker used his credentials), that the hacker had contacted Origin two weeks ago and that the means of ingress was through an employee’s authorisation. In other words the hacker has taken control of the story.  The worst place Origin could be.  And totally avoidable if it had been on top of the facts from the start.  The Australian has skewered Origin’s earlier claims to have a dedicated cyber risk team and various levels of governance such as The Board Audit and the Risk Committee. As the facts tumble out, to the media via a well motivated hacker Origin’s claims are being made to look very foolish.

Large corporations which hold vast amounts of personal information, such as Origin, should have a multi layered cyber defence.  That includes programs that detect unusual activity, such as the exfiltration of data.  They should also have rigorous third party access controls and monitoring of the use of authorisations.

The ABC article provides:

Origin Energy says it is investigating a security breach that “may have” affected customer data.

“Origin Energy Limited (Origin) is currently investigating a potential security incident which may involve unauthorised access to some customers’ data,” it said in a statement.

“We do not believe the impacted data includes customer credit card or bank details.

“We understand an incident like this may raise concerns and acknowledge the impact of this uncertainty on Origin customers.

“Our investigations into this incident are occurring as a matter of urgency, and Origin will provide further updates as appropriate.” Read the rest of this entry »

Partnered health, owner of GP clinics in Australia, suffers significant data breach

July 17, 2026

Partnered Health, a company that owns GP Clinics (and wants to buy more), has suffered a cyber attack in which personal information has been exfiltrated.  Stolen.  Health providers are by far and away the largest sector which suffers reportable data breaches.  Health service providers are notorious for inconsistent and sometimes completely unacceptable privacy and data security practices.  Which seems counter intutive given the strict doctor patient confidentiality obligations and the extensive regulation of the industry.  The explanation is depressingly simple.  First, the culture is poor.  Senior medical professionals are commonly resistant to following proper protocols when it involves data security.  There have been cases where doctors have taken photographs of post operative results and shared with other professionals without the consent of patients.  This “rise above” the rest attitude is poor leadership which trickles down to more junior ranks.  Secondly, clinics and hospitals have large numbers of staff, some casual, using the many terminals and other means of accessing medical records. That poses real problems with password controls and following proper procedure.  Thirdly, there is an IT challenge. Hospitals and clinics often cobble together programs and systems, especially where there is a merger or a takeover, rather than starting fresh with a new system.  That commonly leads to gaps in security.  Fourthly, with a significant churn in staff there is a constant problem of withdrawing authorisations.

The ABC reports on a significant data breach at Partnered Health in Medical records and personal details stolen in GP network cyber attack.   Partnered put out a statement which confirms that data including name, date of birth, address, Medicare and insurance numbers as well as medical information were stolen.  Enough to engage in some identity theft and also very sensitive information.  The information provided is very general. Partnered has come in for some well earned criticism for delaying telling patients for weeks.  The hack was detected on 23 June and Partnered waited until 15 July to publicly advise the public of the attack.

By now there is a good process in dealing with data breaches and poor responses.  Partnered’s approach to date has been less than optimal.

Obvious questions include why data was not siloed and whether it was encrypted.  A hacker accessing names and addresses is one thing.  Having access to notes and medical information is another. It suggests a rather simple set up where no additional authorisation was required to access such sensitive material.  All in one folder perhaps.  Interestingly sites attacked were not all of Partnered’s facilities but less than a quarter of them.  Partnered obtained an ex parte injunction, which is becoming usual practice.  I am not aware of any action being taken for breach of any such injunction.

The article provides:

A network of GP practices and skin cancer clinics has been hit in a major cyber attack, with personal medical records stolen.

Partnered Health, which runs 57 clinics across the country, posted an incident report to its website confirming that patients’ medical records were accessed and taken in the cyber breach. Read the rest of this entry »

Quantum computing and cyber security

July 16, 2026

It is no secret that the advent of quantum computing will have a dramatic impact on cyber security and privacy.  I have written on this threat in 2023 and 2022.  Quantum computing will undermine the effectiveness of cryptographic keys (see my post here).  In the main this threat has not been the focus of many businesses.  That is a significant problem.

The UK Information Commissioner’s Office has published some excellent material on quantum computing and its impact on privacy and data security; Quantum computing,Quantum sensing and imaging in healthcare and ICO tech futures: quantum technologies.   The NIST has published some excellent guidelines dealing with the impact of quantum computing on algorithms and current standards of encryption.

Today the ABC has published a very useful article,  Q-Day and the race to protect your data from quantum attack, on quantum computing and the threat of cyber attack.  It is a good introduction to what is a growing and complicated area of mathematics and practical measures to counter it for cyber security.

It provides:

Imagine this.

You’re catching up on some emails. Verifying your identity with a passport picture. Paying an invoice with your bank details.

In the background, a “bad actor” is collecting all of your encrypted emails. Read the rest of this entry »

The PM’s speech on AI

Today the Prime Minister made what has been reported as a signficant speech on Australia and AI, AI in Australia’s interests,  It is relevant to note that the Privacy Commissioner wrote about AI and privacy in July 2025. It is trite to say artificial intelligence will have a significant impact on most industries and lives in general.  What is not appreciated is how it will change the whole dynamics of cyber security and privacy.  

The PM’s speech is broad brush, as it must be.  It is only when the proposals are firmed up and legislation introduced that the scope of the regulation can be assessed.

The PM’s speech provides:

It’s great to be back at Sydney University, a place that holds so many fond memories.

When I was studying economics here in the 1980s, the world was being taught the meaning of economic rationalism.

Thatcherism in Britain, Reaganomics in the United States.

Yet here in Australia we were making a different choice and moving in a different direction.

Because while other nations were being remade by a philosophy which held there is ‘no such thing as society’.

Australia was building what has become one of the truest expressions of our society, and the duty we owe to each other as members of it, I speak of course of Medicare.

That was an act of economic reform, of social justice – and a statement of national ambition.

In creating Medicare, Australia didn’t beg or borrow from elsewhere.

We built for the best, by building for ourselves.

That thread runs through our national story.

As innovators and inventors, in science and research, in agriculture and energy.

And in democracy, progress and fairness too.

Back when the industrial revolution was fundamentally altering the shape of the economy and the nature of work the minimum wage and eight-hour day were radical experiments.

Today, those Australian ideas are rights that workers have fought for and won around the globe. Read the rest of this entry »

Privacy Commissioner releases report on data breach notifications in 2025. No surprises. An all time high. And those are just the data breaches reported

July 13, 2026

The data breach notification scheme provides some insight into the breadth and depth of data breaches affecting Australian organisations and governmental bodies.  The reports under the scheme are a fraction of the data breaches suffered.  The legislation is complicated and allows sufficient self assessment. This reduces reporting.  There remains a culture of reluctance to publicise, even to a government agency and no one else, any data breach for as long as possible. Poor regulation and weak enforcement over many years has encouraged this approach.

In any event the figures released by the Privacy Commissioner reveal that there were 1,205 data breaches in 2025.  That is an 8% increase over 2024.  Cyber hacking is the main cause of data breaches.  No surprises that health providers are the most breached.  The opportunities to breach a health network are legion and the culture is at best uneven.

The media release provides:

Newly published statistics reveal that 2025 saw the highest number of data breach notification being reported to the Office of the Australian Information Commissioner (OAIC) since the mandatory data breach reporting scheme commenced in 2018. The OAIC received 1,205 data breach notifications in the 2025 calendar year, representing an 8% increase over 2024 (1,112 notifications).

Businesses and Commonwealth government agencies covered by the Privacy Act are required to report any data breach that is likely to result in serious harm to affected individuals under the notifiable data breach scheme.

Cyber hacking remains the primary cause of data breaches reported to the OAIC. Of the 1,205 data breaches notified in 2025, the majority were attributable to malicious or criminal activity (716 notifications), with health service providers the most commonly affected, and accounting for 19% of the total or 225 notifications. Read the rest of this entry »

UK Information Commissioner releases guidance on Internet of Things used in products and services

The internet of things has long been recognised as a significant weakness in cyber security and privacy.  The Information Commissioner has published its final guidance on consumer Internet of Things products and services.

It is a very comprehensive guideline, running to 90 pages, but is laid out in a very user friendly manner.

The media release provides:

We have today published our finalised guidance on consumer Internet of Things (IoT) products and services, setting out clear expectations for manufacturers and developers on how to use people’s personal information responsibly. 

The guidance reflects feedback from both the public and industry following a 12-week consultation last year. It provides regulatory certainty on areas such as how to ask for informed consent, how to provide transparent privacy information and what tools need to be available for people to exercise their rights over their data. 

William Malcolm, ICO Executive Director for Regulatory Risk and Innovation, said:

“Connected devices process some of the most sensitive data about people’s lives, from data about health to daily routines and family life. Product and device innovation holds huge potential to make a positive impact in so many areas of people’s lives, but that innovation must work for everyone. It is vital that product developers put privacy at the centre of product design and use data fairly and transparently. 

“We’ve welcomed the constructive engagement from industry during the consultation process and now we are calling for action – data protection by design is a legal requirement, not a suggestion. We encourage organisations making and developing smart products to review the guidance and ensure they are meeting the standards the public expect.” 

Read the rest of this entry »

Government warning over doctors’ use of AI compromising privacy

July 5, 2026

The pick up in the use of artificial intelligence is not matched by the care to ensure that the user does not compromise his or her patients’/customers’/clients’ privacy.  In the health industry the AI scribe tools are becoming common.  Using AI with patient information runs real risks about that information finding its way into other person’s control.

These issue are covered in the Guardian article Doctors’ soaring use of AI scribes prompts Australian government warning over privacy which provides:

The federal health department has raised concerns about the use of AI scribes by doctors as the health regulator considers the need for safeguards around the technology.

AI scribe tools record, transcribe and summarise conversations between doctors and patients for medical notes, and have boomed in popularity in the past 18 months.

According to an online poll by the Royal Australian College of General Practitioners (RACGP), use of AI scribes by doctors in Australia nearly doubled from 22% in August 2024 to 40% in November 2025.

Companies offering the technology to practitioners say it has been used hundreds of millions of times across the globe in the past 18 months alone as doctors seek to ease the administrative burden of patient consultations. Read the rest of this entry »

The House of Representatives commences inquiry into cyber security for small to medium sized businesses and Organisations

The House Select Committee on Cyber Security for Small to Medium Sized Businesses and Organisations was established by a resolution of appointment that passed the House of Representatives on 4 June 2026.

The Committee will inquiry into:

  1. the cyber maturity of Australian small to medium sized businesses and organisations, including not-for-profit organisations;
  2. the adequacy, appropriateness and accessibility of guidance provided to small to medium sized businesses and organisations by Government in relation to cyber security;
  3. whether there are appropriate standards for small to medium sized businesses and organisations in relation to cyber security;
  4. the ease for small to medium sized businesses and organisations to procure appropriate cyber security services in Australia;
  5. the importance of training for employees on good cyber security practices to the overall cyber security of small to medium sized businesses and organisations;
  6. the impact of cyber security maturity on the feasibility for small to medium businesses and organisations to participate in Government and large corporate supply chains; and
  7. any other related matters;

The Committee will present its final report by 31 March 2027.

The relevant page on the Read the rest of this entry »

Prime Minister’s bank records accessed, breach of privacy

July 2, 2026

People looking into other peoples bank accounts without authority is a longstanding and chronic problem in banks and other financial institutions. It gave rise to a ground breaking case recognising a cause of action for breach of privacy in Canada with the case of Jones v Tsige in 2012. Often the breaches involve a person checking on the accounts of a family member, partner or neighbour.  Banks have quite good controls to detect such suspicious activity.  The almost invariable outcome is instant quiet termination.  But the unauthorised access into Prime Minister Albanese’s banking records is not low key and the result has not been quiet dismissal.  As the Australian reports with Ernst & Young graduate charged over allegedly accessing prime minister’s bank details it has been high profile and charges have been laid against the alleged snooper.  As the story notes the bank in question, the CBA, discovered the breach when its internal system triggered a flag.  That is the common method.

While the Prime Minister almost certainly has a claim for serious invasion of privacy against the EY graduate whether he does anything is another question.

The article provides:

A graduate from Ernst & Young has been charged after allegedly accessing the prime minister’s banking details.

Another person has also been charged in connection with the alleged incident, who is understood not to be employed by EY.

It is alleged they accessed the material while one of pair was on secondment at the Commonwealth Bank.

The EY graduate was terminated from their employment after an internal investigation.

CBA is believed to have alerted EY after the bank’s internal system triggered a flag.

The Australian Federal Police said they charged two Sydney men on May 6, with allegedly accessing restricted personal banking data belonging to a federal parliamentarian. Read the rest of this entry »

New South Wales Auditor General highlights inadequacy of security and privacy protections in NSW public schools

June 29, 2026

Schools are mass collectors of data, much of it very sensitive. Details of children enrolled in classes, their medical and pyschological issues are enthusiastically collected. Phone numbers and addresses of parents, guardians and other relatives are provided to schools. Today the Auditor General in New South Wales released a report highlighting the problems with the current system in NSW schools.

It is very much a mixed report card.  While the department has structures and policies in place there is a very imperfect implementation and monitoring.  There is a real problems with apps schools use with much sensitive data accessible by third party providers.

The department states there were 491 suspected data breach matters resolved from 2023 to 2025 that involved student information:

    • 435 matters were assessed as being a data breach but not an eligible data breach
    • 6 matters met the threshold to constitute an eligible data breach
    • 1 matter was assessed as a non-department data breach
    • 35 matters were assessed as not being a data breach
    • 12 were not data breaches but involved related queries from schools
    • 2 were duplicate

In 83% of cases the suspected data breaches in 2024–25 were the result of human error, such as access control errors, email errors, permission-to-publish errors and staff misconduct. Other causes included loss or theft (7%), system faults (5%) or cyber incidents (3%).

Incidents

  • The personal mobile phones of 2 department staff were compromised through SIM-swap attacks that compromised both their personal and department accounts. The threat actor accessed the personal information of students, staff and
  • This breach was classified and handled as an eligible data breach, and the department notified affected individuals (with the help of ID Support NSW) and the The department advised it took other actions in response to the breach including:
    • moving staff members who fell victim to the attack from text message multi-factor authentication to Microsoft authenticator with passkeys
    • completing an internal audit to ascertain and revise down the extent of the personal information accessed by the threat actor
    • engaging external service providers to ensure the department had met the regulatory requirements under the privacy legislation
    • implementing phishing-resistant multi-factor authentication software for all employees (currently within the pilot phase).

Unauthorised disclosure of information

  • A school shared photos of 3 students on its Facebook page without parental consent and despite enrolment forms indicating no permission. After a family raised concerns via email, the school removed the
  • A staff member used the school’s third-party school administration system to send text messages to parents about their child’s absence from school. Instead of the text messages going only to the children’s parents, they went to the children’s emergency contacts and other children’s parents. After identifying this breach, the school reverted the settings on the third-party school administration system to their correct
  • A community member found volumes of school paper records containing student information dumped at a building construction site. The department recovered and digitised the records.

The snapshot of the report provides:

Key findings

The department has established a range of controls to manage the security and privacy of student information

Over the last 3 years, the department has strengthened its controls by uplifting cyber security capability, centrally contracting key third-party IT vendors, developing specific policy frameworks, and providing professional learning and centralised supports for schools.

Technical responsibilities have been allocated to school principals without sufficient departmental oversight

The department does not clearly define the specific risks to student information that schools must manage, nor provide clear operational guidance or proactive support to monitor how legislative and policy requirements are met in practice at the school level. With principals relying on their own judgement and capacity, practices are inconsistent and in some cases non-compliant. Read the rest of this entry »