Origin cyber attack, hugely embarrassing and poorly managed
July 23, 2026
Utilities and telcos are prime targets of cyber attack. The number of unsuccessful attacks are rarely publicised. The successful attacks which involve access to large amounts of data are well publicised. As the recent attack on Origin energy proves. Not surprising given the hacker claims to have accessed records of 2 million customers. It has been reported by the ABC, Nine, News.com, cyber daily and others. Origin has sort of confirmed there was a data breach and has released a wholly inadequate statement which it describes as a potential customer data breach. A dreadful approach. Saying less than very little and leaving customers wondering. if not anxious, about what happened to their personal information. Its attempt at minimising concern is to say that it didn’t believe bank records or credit card details were stolen. Even then it was very qualified. Even if it did not know the full scope of the data breach it could have provided a better response. There is now a skill on how to respond. Which Origin does not possess.
What is very disappointing, more than its non statement statement, is that Origin Energy was made aware of the cyber attack almost three weeks ago. By the hacker. And to make matters worse the hacker contacted the Australian 2 days ago. Origin gave the impression then that no data had been stolen. So the next day the hacker provided a sample of 50 customer records to the Australian. The immediate reaction from Origin was dreadful. The fact that Origin contacted the ASX after being notified by the media bespeaks a serious problem with Origin’s data breach response plan. If such a plan existed. If it existed then the likely explanation was that Origin adopted a low profile and hoped it would all go away. An attitude some companies still take and a product of long standing poor regulation in the past and even worse enforcement until recently. The situation got worse for Origin today when the hacker told the Australian that Origin sacked an employee after accusing him or her of being behind the data breach (even though the hacker used his credentials), that the hacker had contacted Origin two weeks ago and that the means of ingress was through an employee’s authorisation. In other words the hacker has taken control of the story. The worst place Origin could be. And totally avoidable if it had been on top of the facts from the start. The Australian has skewered Origin’s earlier claims to have a dedicated cyber risk team and various levels of governance such as The Board Audit and the Risk Committee. As the facts tumble out, to the media via a well motivated hacker Origin’s claims are being made to look very foolish.
Large corporations which hold vast amounts of personal information, such as Origin, should have a multi layered cyber defence. That includes programs that detect unusual activity, such as the exfiltration of data. They should also have rigorous third party access controls and monitoring of the use of authorisations.
The ABC article provides:
Origin Energy says it is investigating a security breach that “may have” affected customer data.
“Origin Energy Limited (Origin) is currently investigating a potential security incident which may involve unauthorised access to some customers’ data,” it said in a statement.
“We do not believe the impacted data includes customer credit card or bank details.
“We understand an incident like this may raise concerns and acknowledge the impact of this uncertainty on Origin customers.
“Our investigations into this incident are occurring as a matter of urgency, and Origin will provide further updates as appropriate.” Read the rest of this entry »