Origin now admits to cyber breach affect 900,000 after “initial review”. The dreadful response to this data breach continues

July 28, 2026

In my experience organisations that do not have a data breach response plan, which they test and rehearse, suffer for it when there is a data breach.  Those organisations  commonly resist engaging with the community, media or even government.  That may suit some businesses but does not help when dealing with a data breach, where controlled transparency is a positive trait.  If Origin had a data breach response plan it probably has it locked away in a safe and the board of directors have forgotten the combination.

A good data breach response plan has a list of tasks that need to be attended to and a a specified group of people who have specific tasks to do.  It should also have contact details of experts to contact; technical, media, legal, human resources.  There needs to be as much done in the first 24 hours as possible to set up a coherent response.

Origin’s response to this data breach has been uniformly dreadful.  It’s initial response came when it was told there was a data breach.  Then it was incredibly cagey and defensive.  Then it was vague.  Then there was a partial admission without identifying how many customers were affected.  And today it provides an initial review, whatever that means, which identifies 900,000 customers, and former customers, affected.  Could be as high as 20% of the customers.  That is bound to be an understatement.  What is difficult to square is why it is taking so long to get a good idea of the scope of the attack. As Origin says, it was aware of a “potential security threat” since early July and then on 22 July some new information indicated a “potential security incident“.   It is so vague as to be meaningless.  So there was no breach in early July? Or was there?  If the threat was identified what was done so as to avoid an incident?  Sometimes organisations think it is clever by to use vague terminology to say nothing but claim they are saying something.  It rarely works as well as they think it might.  Here it falls at the first hurdle.  It makes little sense and begs more questions than it answers.  Origin’s problems have been compounded by the fact that the hacker has engaged with the media, specifically the Australian.  That happens occasionally but can be managed as well.  Origin has not managed that side of things well either.

Something very odd is going on at Origin.

Today’s Origin statement Read the rest of this entry »

Origin energy data breach…a salutory lesson ofwhat happens when you don’t respond quickly, candidly and coherently from the outset

July 27, 2026

The Origin energy data breach has been handled very badly by Origin to date.  That is not to say it has not been trying harder.  Often how an organisation responds in the first few days of a data breach sets the tone. That is certainly the experience in the United States.  Here the culture is less attuned to having a data breach recovery plan and there is less effort in wargaming what would happen if there is a data breach.

Origin put out a statement on Thursday which said not much of anything:

Origin Energy Limited (Origin) provides the following update on its data security incident.  

Origin can confirm there has been unauthorised access and disclosure of some customers’ data. 

We are working to understand the total number of impacted customers, and we will contact any customers where we can confirm they have been affected.  

For affected customers, impacted data may include name, address, date of birth, contact phone number and account information, as well as the last four digits of a credit card, or the last three digits of a bank account. Incomplete credit card or bank account information cannot be used to make purchases or access accounts. 

Origin CEO Frank Calabria said, “I’m sorry this has happened. Customers trust Origin with their information, and I apologise for the impact this may cause. 

“We are contacting affected customers, offering support and have set up a dedicated contact number and additional resources to help manage our response to this incident. 

“One of our key priorities is taking action to secure our systems and ensure no further unauthorised access. We are working with independent cyber experts to support Origin, and that work is continuing alongside the work of authorities,” Mr Calabria said. 

Origin continues to engage with Australian Government agencies, including the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner. 

It now admits there was a data breach rather than a “potential security incident” and says names, addresses, dates of birth, contact phone numbers and account information being leaked and the incomplete portions of credit cards and bank details were affected.  The rest is a word salad of platitudes and the usual boilerplate of working with government agencies. It is a sub par statement.

Meanwhile the media has filled in the gaps Origin can’t or won’t and speculates.  Cyber security Insiders reports with Origin Energy Sector Data Breach Widens to 5 Million Customers the flaws in Read the rest of this entry »

Origin cyber attack, hugely embarrassing and poorly managed

July 23, 2026

Utilities and telcos are prime targets of cyber attack.  The number of unsuccessful attacks are rarely publicised.  The successful attacks which involve access to large amounts of data are well publicised.  As the recent attack on Origin energy proves.  Not surprising given the hacker claims to have accessed records of 2 million customers.  It has been reported by the ABCNineNews.com, cyber daily and others.  Origin has sort of confirmed there was a data breach and has released a wholly inadequate statement which it describes as a potential customer data breach.  A dreadful approach.  Saying less than very little and leaving customers wondering. if not anxious, about what happened to their personal information.  Its attempt at minimising concern is to say that it didn’t believe bank records or credit card details were stolen.  Even then it was very qualified.  Even if it did not know the full scope of the data breach it could have provided a better response.  There is now a skill on how to respond.  Which Origin does not possess.

What is very disappointing, more than its non statement statement, is that Origin Energy was made aware of the cyber attack almost three weeks ago.  By the hacker.  And to make matters worse the hacker contacted the Australian 2 days ago.  Origin gave the impression then that no data had been stolen.  So the next day the hacker provided a sample of 50 customer records to the Australian.  The immediate reaction from Origin was dreadful.  The fact that Origin contacted the ASX after being notified by the media bespeaks a serious problem with Origin’s data breach response plan.  If such a plan existed.  If it existed then the likely explanation was that Origin adopted a low profile and hoped it would all go away.  An attitude some companies still take and a product of long standing poor regulation in the past and even worse enforcement until recently. The situation got worse for Origin today when the hacker told the Australian that Origin sacked an employee after accusing him or her of being behind the data breach (even though the hacker used his credentials), that the hacker had contacted Origin two weeks ago and that the means of ingress was through an employee’s authorisation. In other words the hacker has taken control of the story.  The worst place Origin could be.  And totally avoidable if it had been on top of the facts from the start.  The Australian has skewered Origin’s earlier claims to have a dedicated cyber risk team and various levels of governance such as The Board Audit and the Risk Committee. As the facts tumble out, to the media via a well motivated hacker Origin’s claims are being made to look very foolish.

Large corporations which hold vast amounts of personal information, such as Origin, should have a multi layered cyber defence.  That includes programs that detect unusual activity, such as the exfiltration of data.  They should also have rigorous third party access controls and monitoring of the use of authorisations.

The ABC article provides:

Origin Energy says it is investigating a security breach that “may have” affected customer data.

“Origin Energy Limited (Origin) is currently investigating a potential security incident which may involve unauthorised access to some customers’ data,” it said in a statement.

“We do not believe the impacted data includes customer credit card or bank details.

“We understand an incident like this may raise concerns and acknowledge the impact of this uncertainty on Origin customers.

“Our investigations into this incident are occurring as a matter of urgency, and Origin will provide further updates as appropriate.” Read the rest of this entry »

Partnered health, owner of GP clinics in Australia, suffers significant data breach

July 17, 2026

Partnered Health, a company that owns GP Clinics (and wants to buy more), has suffered a cyber attack in which personal information has been exfiltrated.  Stolen.  Health providers are by far and away the largest sector which suffers reportable data breaches.  Health service providers are notorious for inconsistent and sometimes completely unacceptable privacy and data security practices.  Which seems counter intutive given the strict doctor patient confidentiality obligations and the extensive regulation of the industry.  The explanation is depressingly simple.  First, the culture is poor.  Senior medical professionals are commonly resistant to following proper protocols when it involves data security.  There have been cases where doctors have taken photographs of post operative results and shared with other professionals without the consent of patients.  This “rise above” the rest attitude is poor leadership which trickles down to more junior ranks.  Secondly, clinics and hospitals have large numbers of staff, some casual, using the many terminals and other means of accessing medical records. That poses real problems with password controls and following proper procedure.  Thirdly, there is an IT challenge. Hospitals and clinics often cobble together programs and systems, especially where there is a merger or a takeover, rather than starting fresh with a new system.  That commonly leads to gaps in security.  Fourthly, with a significant churn in staff there is a constant problem of withdrawing authorisations.

The ABC reports on a significant data breach at Partnered Health in Medical records and personal details stolen in GP network cyber attack.   Partnered put out a statement which confirms that data including name, date of birth, address, Medicare and insurance numbers as well as medical information were stolen.  Enough to engage in some identity theft and also very sensitive information.  The information provided is very general. Partnered has come in for some well earned criticism for delaying telling patients for weeks.  The hack was detected on 23 June and Partnered waited until 15 July to publicly advise the public of the attack.

By now there is a good process in dealing with data breaches and poor responses.  Partnered’s approach to date has been less than optimal.

Obvious questions include why data was not siloed and whether it was encrypted.  A hacker accessing names and addresses is one thing.  Having access to notes and medical information is another. It suggests a rather simple set up where no additional authorisation was required to access such sensitive material.  All in one folder perhaps.  Interestingly sites attacked were not all of Partnered’s facilities but less than a quarter of them.  Partnered obtained an ex parte injunction, which is becoming usual practice.  I am not aware of any action being taken for breach of any such injunction.

The article provides:

A network of GP practices and skin cancer clinics has been hit in a major cyber attack, with personal medical records stolen.

Partnered Health, which runs 57 clinics across the country, posted an incident report to its website confirming that patients’ medical records were accessed and taken in the cyber breach. Read the rest of this entry »

Quantum computing and cyber security

July 16, 2026

It is no secret that the advent of quantum computing will have a dramatic impact on cyber security and privacy.  I have written on this threat in 2023 and 2022.  Quantum computing will undermine the effectiveness of cryptographic keys (see my post here).  In the main this threat has not been the focus of many businesses.  That is a significant problem.

The UK Information Commissioner’s Office has published some excellent material on quantum computing and its impact on privacy and data security; Quantum computing,Quantum sensing and imaging in healthcare and ICO tech futures: quantum technologies.   The NIST has published some excellent guidelines dealing with the impact of quantum computing on algorithms and current standards of encryption.

Today the ABC has published a very useful article,  Q-Day and the race to protect your data from quantum attack, on quantum computing and the threat of cyber attack.  It is a good introduction to what is a growing and complicated area of mathematics and practical measures to counter it for cyber security.

It provides:

Imagine this.

You’re catching up on some emails. Verifying your identity with a passport picture. Paying an invoice with your bank details.

In the background, a “bad actor” is collecting all of your encrypted emails. Read the rest of this entry »

The PM’s speech on AI

Today the Prime Minister made what has been reported as a signficant speech on Australia and AI, AI in Australia’s interests,  It is relevant to note that the Privacy Commissioner wrote about AI and privacy in July 2025. It is trite to say artificial intelligence will have a significant impact on most industries and lives in general.  What is not appreciated is how it will change the whole dynamics of cyber security and privacy.  

The PM’s speech is broad brush, as it must be.  It is only when the proposals are firmed up and legislation introduced that the scope of the regulation can be assessed.

The PM’s speech provides:

It’s great to be back at Sydney University, a place that holds so many fond memories.

When I was studying economics here in the 1980s, the world was being taught the meaning of economic rationalism.

Thatcherism in Britain, Reaganomics in the United States.

Yet here in Australia we were making a different choice and moving in a different direction.

Because while other nations were being remade by a philosophy which held there is ‘no such thing as society’.

Australia was building what has become one of the truest expressions of our society, and the duty we owe to each other as members of it, I speak of course of Medicare.

That was an act of economic reform, of social justice – and a statement of national ambition.

In creating Medicare, Australia didn’t beg or borrow from elsewhere.

We built for the best, by building for ourselves.

That thread runs through our national story.

As innovators and inventors, in science and research, in agriculture and energy.

And in democracy, progress and fairness too.

Back when the industrial revolution was fundamentally altering the shape of the economy and the nature of work the minimum wage and eight-hour day were radical experiments.

Today, those Australian ideas are rights that workers have fought for and won around the globe. Read the rest of this entry »

Privacy Commissioner releases report on data breach notifications in 2025. No surprises. An all time high. And those are just the data breaches reported

July 13, 2026

The data breach notification scheme provides some insight into the breadth and depth of data breaches affecting Australian organisations and governmental bodies.  The reports under the scheme are a fraction of the data breaches suffered.  The legislation is complicated and allows sufficient self assessment. This reduces reporting.  There remains a culture of reluctance to publicise, even to a government agency and no one else, any data breach for as long as possible. Poor regulation and weak enforcement over many years has encouraged this approach.

In any event the figures released by the Privacy Commissioner reveal that there were 1,205 data breaches in 2025.  That is an 8% increase over 2024.  Cyber hacking is the main cause of data breaches.  No surprises that health providers are the most breached.  The opportunities to breach a health network are legion and the culture is at best uneven.

The media release provides:

Newly published statistics reveal that 2025 saw the highest number of data breach notification being reported to the Office of the Australian Information Commissioner (OAIC) since the mandatory data breach reporting scheme commenced in 2018. The OAIC received 1,205 data breach notifications in the 2025 calendar year, representing an 8% increase over 2024 (1,112 notifications).

Businesses and Commonwealth government agencies covered by the Privacy Act are required to report any data breach that is likely to result in serious harm to affected individuals under the notifiable data breach scheme.

Cyber hacking remains the primary cause of data breaches reported to the OAIC. Of the 1,205 data breaches notified in 2025, the majority were attributable to malicious or criminal activity (716 notifications), with health service providers the most commonly affected, and accounting for 19% of the total or 225 notifications. Read the rest of this entry »

UK Information Commissioner releases guidance on Internet of Things used in products and services

The internet of things has long been recognised as a significant weakness in cyber security and privacy.  The Information Commissioner has published its final guidance on consumer Internet of Things products and services.

It is a very comprehensive guideline, running to 90 pages, but is laid out in a very user friendly manner.

The media release provides:

We have today published our finalised guidance on consumer Internet of Things (IoT) products and services, setting out clear expectations for manufacturers and developers on how to use people’s personal information responsibly. 

The guidance reflects feedback from both the public and industry following a 12-week consultation last year. It provides regulatory certainty on areas such as how to ask for informed consent, how to provide transparent privacy information and what tools need to be available for people to exercise their rights over their data. 

William Malcolm, ICO Executive Director for Regulatory Risk and Innovation, said:

“Connected devices process some of the most sensitive data about people’s lives, from data about health to daily routines and family life. Product and device innovation holds huge potential to make a positive impact in so many areas of people’s lives, but that innovation must work for everyone. It is vital that product developers put privacy at the centre of product design and use data fairly and transparently. 

“We’ve welcomed the constructive engagement from industry during the consultation process and now we are calling for action – data protection by design is a legal requirement, not a suggestion. We encourage organisations making and developing smart products to review the guidance and ensure they are meeting the standards the public expect.” 

Read the rest of this entry »

Government warning over doctors’ use of AI compromising privacy

July 5, 2026

The pick up in the use of artificial intelligence is not matched by the care to ensure that the user does not compromise his or her patients’/customers’/clients’ privacy.  In the health industry the AI scribe tools are becoming common.  Using AI with patient information runs real risks about that information finding its way into other person’s control.

These issue are covered in the Guardian article Doctors’ soaring use of AI scribes prompts Australian government warning over privacy which provides:

The federal health department has raised concerns about the use of AI scribes by doctors as the health regulator considers the need for safeguards around the technology.

AI scribe tools record, transcribe and summarise conversations between doctors and patients for medical notes, and have boomed in popularity in the past 18 months.

According to an online poll by the Royal Australian College of General Practitioners (RACGP), use of AI scribes by doctors in Australia nearly doubled from 22% in August 2024 to 40% in November 2025.

Companies offering the technology to practitioners say it has been used hundreds of millions of times across the globe in the past 18 months alone as doctors seek to ease the administrative burden of patient consultations. Read the rest of this entry »

The House of Representatives commences inquiry into cyber security for small to medium sized businesses and Organisations

The House Select Committee on Cyber Security for Small to Medium Sized Businesses and Organisations was established by a resolution of appointment that passed the House of Representatives on 4 June 2026.

The Committee will inquiry into:

  1. the cyber maturity of Australian small to medium sized businesses and organisations, including not-for-profit organisations;
  2. the adequacy, appropriateness and accessibility of guidance provided to small to medium sized businesses and organisations by Government in relation to cyber security;
  3. whether there are appropriate standards for small to medium sized businesses and organisations in relation to cyber security;
  4. the ease for small to medium sized businesses and organisations to procure appropriate cyber security services in Australia;
  5. the importance of training for employees on good cyber security practices to the overall cyber security of small to medium sized businesses and organisations;
  6. the impact of cyber security maturity on the feasibility for small to medium businesses and organisations to participate in Government and large corporate supply chains; and
  7. any other related matters;

The Committee will present its final report by 31 March 2027.

The relevant page on the Read the rest of this entry »