Origin now admits to cyber breach affect 900,000 after “initial review”. The dreadful response to this data breach continues
July 28, 2026
In my experience organisations that do not have a data breach response plan, which they test and rehearse, suffer for it when there is a data breach. Those organisations commonly resist engaging with the community, media or even government. That may suit some businesses but does not help when dealing with a data breach, where controlled transparency is a positive trait. If Origin had a data breach response plan it probably has it locked away in a safe and the board of directors have forgotten the combination.
A good data breach response plan has a list of tasks that need to be attended to and a a specified group of people who have specific tasks to do. It should also have contact details of experts to contact; technical, media, legal, human resources. There needs to be as much done in the first 24 hours as possible to set up a coherent response.
Origin’s response to this data breach has been uniformly dreadful. It’s initial response came when it was told there was a data breach. Then it was incredibly cagey and defensive. Then it was vague. Then there was a partial admission without identifying how many customers were affected. And today it provides an initial review, whatever that means, which identifies 900,000 customers, and former customers, affected. Could be as high as 20% of the customers. That is bound to be an understatement. What is difficult to square is why it is taking so long to get a good idea of the scope of the attack. As Origin says, it was aware of a “potential security threat” since early July and then on 22 July some new information indicated a “potential security incident“. It is so vague as to be meaningless. So there was no breach in early July? Or was there? If the threat was identified what was done so as to avoid an incident? Sometimes organisations think it is clever by to use vague terminology to say nothing but claim they are saying something. It rarely works as well as they think it might. Here it falls at the first hurdle. It makes little sense and begs more questions than it answers. Origin’s problems have been compounded by the fact that the hacker has engaged with the media, specifically the Australian. That happens occasionally but can be managed as well. Origin has not managed that side of things well either.
Something very odd is going on at Origin.
Today’s Origin statement Read the rest of this entry »