Origin cyber attack, hugely embarrassing and poorly managed
July 23, 2026 |
Utilities and telcos are prime targets of cyber attack. The number of unsuccessful attacks are rarely publicised. The successful attacks which involve access to large amounts of data are well publicised. As the recent attack on Origin energy proves. Not surprising given the hacker claims to have accessed records of 2 million customers. It has been reported by the ABC, Nine, News.com, cyber daily and others. Origin has sort of confirmed there was a data breach and has released a wholly inadequate statement which it describes as a potential customer data breach. A dreadful approach. Saying less than very little and leaving customers wondering. if not anxious, about what happened to their personal information. Its attempt at minimising concern is to say that it didn’t believe bank records or credit card details were stolen. Even then it was very qualified. Even if it did not know the full scope of the data breach it could have provided a better response. There is now a skill on how to respond. Which Origin does not possess.
What is very disappointing, more than its non statement statement, is that Origin Energy was made aware of the cyber attack almost three weeks ago. By the hacker. And to make matters worse the hacker contacted the Australian 2 days ago. Origin gave the impression then that no data had been stolen. So the next day the hacker provided a sample of 50 customer records to the Australian. The immediate reaction from Origin was dreadful. The fact that Origin contacted the ASX after being notified by the media bespeaks a serious problem with Origin’s data breach response plan. If such a plan existed. If it existed then the likely explanation was that Origin adopted a low profile and hoped it would all go away. An attitude some companies still take and a product of long standing poor regulation in the past and even worse enforcement until recently. The situation got worse for Origin today when the hacker told the Australian that Origin sacked an employee after accusing him or her of being behind the data breach (even though the hacker used his credentials), that the hacker had contacted Origin two weeks ago and that the means of ingress was through an employee’s authorisation. In other words the hacker has taken control of the story. The worst place Origin could be. And totally avoidable if it had been on top of the facts from the start. The Australian has skewered Origin’s earlier claims to have a dedicated cyber risk team and various levels of governance such as The Board Audit and the Risk Committee. As the facts tumble out, to the media via a well motivated hacker Origin’s claims are being made to look very foolish.
Large corporations which hold vast amounts of personal information, such as Origin, should have a multi layered cyber defence. That includes programs that detect unusual activity, such as the exfiltration of data. They should also have rigorous third party access controls and monitoring of the use of authorisations.
The ABC article provides:
Origin Energy says it is investigating a security breach that “may have” affected customer data.
“Origin Energy Limited (Origin) is currently investigating a potential security incident which may involve unauthorised access to some customers’ data,” it said in a statement.
“We do not believe the impacted data includes customer credit card or bank details.
“We understand an incident like this may raise concerns and acknowledge the impact of this uncertainty on Origin customers.
“Our investigations into this incident are occurring as a matter of urgency, and Origin will provide further updates as appropriate.”
The company said it had notified the Australian Cyber Security Centre and Australian Federal Police.
The Australian news outlet reported a hacker had sent it a sample of 50 customer records containing names, addresses, emails, dates of birth, phone numbers and bill history.
The ABC cannot immediately verify these claims.
It is understood that following this, Origin Energy alerted authorities to a potential security breach.
Origin Energy is one of Australia’s leading energy retailers with more than 4.7 million customers.
Upon the announcement shares in the company quickly dropped by 2.5 per cent.
The security breach is the latest for major companies in Australia, with Optus and Medibank both suffering mass breaches in 2022.
Last week Partnered Health, which operates a network of GP clinics, was targeted in a cyber attack, with sensitive medical records and personal information stolen.
The Australian article provides:
The suspected hacker contacted The Australian on Tuesday, saying that Origin had ignored them. We immediately contacted Origin Energy and were given the sense that no data had been compromised.
It wasn’t until early Wednesday morning after the alleged hacker had sent through a sample of 50 customer records to The Australian – and again we immediately forwarded it to Origin – that alarm bells started to ring.
That is a big concern and raises questions about what transpired in the past three weeks when the suspected hacker said they first made contact with Origin.
The fact it took questions from a journalist to trigger an announcement to the ASX and an investigation about a potential breach looks incredibly sloppy by an ASX50 company, and unsophisticated from a hacker.
Typically, cyber security teams immediately notice signs of suspicious activity on a corporate network when people access information that they shouldn’t. And this could become telling in the investigation into what actually transpired and what exactly was “breached”.
But The Australian was told no alarm had been raised. “Despite my outreach to their board members, security teams, and customer care departments, Origin hasn’t made a public announcement about the breach or responded to negotiate next steps. They’ve shown no interest in resolving it before the data goes public,” the alleged hacker said.
The email was from an ordinary Gmail account – no encrypted messaging service or what you would expect from the darker corners of the internet – signing off with “best regards”.
“I’m reaching out because I’d like your outlet to cover how Origin failed to initiate contact and resolve this matter privately and even make a public announcement. If they don’t reach out within 14 days to settle this with us, I will publicly leak the full dataset,” the suspected hacker wrote.
Overnight on Tuesday, the suspected hacker sent another email to The Australian, with the “sample” that contained the personal information, including names, dates of birth, addresses, phone numbers and the billing histories, among other data, of 50 customers. This was forwarded to Origin immediately, and the company made an announcement to the ASX shortly after midday on Wednesday.
Companies receive such claims and threats regularly. Some are extortion attempts. Some aren’t and are genuine. But rarely does a suspected hacker contact the media in a bid to pressure a company to negotiate and go public.
Origin’s investigation will determine whether the alleged hacker’s claims are true and the two million customer records were compromised.
If true, it would rank among Australia’s biggest cyber breaches. Almost 10 million Optus customer records were compromised in 2022, a similar number at Medibank the same year, and 5.7 million at Qantas a year ago.
But what is clear already at Origin is that an email from the suspected hacker containing a “sample” of 50 customer records was enough for the company to contact the AFP, cyber security and privacy regulators, as well as its shareholders.
It was enough to finally ring the alarm bells.
It shows the many methods hackers will adopt to achieve their desired outcome.
And all companies, which sit on troves of personal customer information, should take note.
The second Australian article provides:
Origin Energy sacked an employee after accusing them of being behind one of Australia’s biggest potential data breaches, the self-styled mastermind has claimed.
The $18.4bn electricity and gas titan declined to comment whether IT fired one of its workers over the online assault, which prompted an “urgent” investigation following questions from The Australian.
On Thursday afternoon, Origin said in a statement to the ASX that it “can confirm there has been unauthorised access and disclosure of some customers’ data”
The company this included the last four digits of a credit card or the last three digits of a bank account after saying on Wednesday that it did “not believe” such data was accessed.
CEO apologises
Origin chief executive Frank Calabria said he was “sorry this has happened”.
“Customers trust Origin with their information, and I apologise for the impact this may cause. “We are contacting affected customers, offering support and have set up a dedicated contact number and additional resources to help manage our response to this incident,” Mr Calabria said.
The suspected hacker contacted Origin almost three weeks ago claiming that they had accessed two million customer records. They said they used an employee’s logon to access Origin’s system but did not say how they obtained that logon.
The suspected hacker has threatened to publish the data in two weeks, saying Origin “failed to initiate contact and resolve this matter privately”.
Origin launched an investigation, notified the AFP and other authorities, and told shareholders on Wednesday after The Australian forwarded a ‘sample’ of 50 customer records sent by the alleged hacker on Tuesday night.
Alleged motivation
The suspected hacker says the reason they targeted the company was because it had sent customer support roles overseas.
Origin operates a hybrid customer support model, employing staff in Australia as well as outsourcing to global service providers at Manila in the Philippines. It completed two redundancy rounds as part of the offshoring move last year.
“I had access to their customer tools for three weeks, and their IT team didn’t detect anything before I managed to dump the data of two million users. I did this because Origin hires customer care agents offshore to save money,” the alleged hacker wrote in an email under the name of Edison Walthour.
Origin Energy email to customers when it previously thought no credit card or bank details had been accessed.
“The people in Asia work hard but get underpaid heavily. They don’t care about customer security at all. They just care about saving money.”
Origin began notifying their customers late on Wednesday. “We are contacting all Origin customers as a precaution while we conduct a thorough investigation into the potential impact of this incident,” the company wrote.
“We sincerely apologise for the uncertainty this may cause.”
Potential fines
Australian companies face fines of up to $50m or 30 per cent of their revenue for severe data mishandling. Origin is the nation’s biggest energy retailer. In the six months to December 31 its revenue totalled almost $8bn. That equates to a potential maximum fine of $2.34bn.
The alleged hacker has not revealed how they accessed an employee logon. Instead they have aired frustration at Origin’s response to their claims.
It is understood that Origin requested evidence from the alleged hacker over the breach but they didn’t respond.
Cyber response
Typically, cyber security teams immediately notice signs of suspicious activity on a corporate network when people access information that they shouldn’t. And this could become telling in the investigation into what actually transpired and what exactly was “breached”.
Origin has said previously that it has a “dedicated cyber risk team that is responsible for implementing our board-approved cyber strategy, and we seek to continuously improve our security resilience and safeguard our critical assets and customers’ data”
“Cyber security risks are governed at multiple levels. The Board Audit and Risk Committee has overall governance accountability, and business units are responsible for adequate controls within their technology platforms and business processes,” Origin said in its 2025 ‘Sustainability Management Approaches’ document.
The suspected hacker said Origin was “100 per cent aware” of their claims before The Australian contacted the company this week.
“They interviewed the employee whose credentials I used, even fired him, and accused him of being behind it,” they wrote in an email.
“I emailed all their board members and security teams; no one responded, but they’ve definitely seen my message.”
The alleged hacker said the planned to publish the data – which contains names, dates of birth, address, emails, phone numbers and billing history among other information – citing that inaction.
On Tuesday, they gave Origin a 14-day deadline.
“Since they aren’t responding or making an announcement about it, the only reasonable next step is to publish the data publicly,” the suspected hacker said. This was after Origin had made the statement to the ASX.
The suspected hacker also sent screenshots, which The Australian forwarded immediately to Origin, of customer records accessed on its customer management platform supplied by Kraken, which says it has delivered a “$170m saving in cost-to-serve”.
Why it’s a concern
RMIT associate professor Nalin Arachchilage says names, addresses, account numbers and usage data are “exactly the kind of information attackers use to build convincing scams – and increasingly, to profile a household for years to come, not just for the next billing cycle”.
“With incidents like these, it isn’t just what can be done with the data today – it’s what can be done with it in ten years’ time. We’re seeing a growing pattern of ‘harvest now, decrypt later’ attacks, where adversaries steal encrypted data now simply to sit on it, betting that quantum computing will eventually be powerful enough to break the encryption protecting it,” associate professor Arachchilage said.
“It’s a bit like someone secretly recording every phone call you’ve ever made, even though they can’t understand a word of it yet. They’re not listening for what you’re saying today – they’re banking on inventing the ability to decode it later. When that day comes, years-old ‘unreadable’ data can suddenly become very readable.”
Associate professor Arachchilage said critical industries like energy retailers hold “long-shelf-life data” that makes ‘harvest now, decrypt later’ worthwhile for attackers.
“Identity details, account histories, household patterns … don’t expire the way a stolen password does. Critical infrastructure and essential services need to be considered for post-quantum cryptography, not an afterthought.”
Origin said incomplete credit card or bank account information cannot be used to make purchases or access accounts.
Australian companies targeted
If alleged hacker’s claims are true it would rank alongside Australia’s biggest data breaches. A mass breach hit a Qantas call centre database – housed in Manila – exposing names, addresses, phone numbers, birth dates and emails. Frequent flyer numbers, status, and seat and meal preferences were also held on the database.
But the Office of the Australian Information Commissioner last week said preliminary inquiries showed the airline had not failed in its responsibility to protect personal data.
In 2022, the personal details of almost 10 million Medibank customers were stolen after a criminal bought login credentials to gain access to the network from an online Russian criminal forum. They also did extensive reconnaissance before collecting the data, which experts estimate would have lasted months.
A 15-month-long investigation led by the Australian Federal Police and the Australian Signals Directorate later identified Russian Aleksandr Ermakov as the mastermind behind the Medibank attack.
Almost three weeks ago, several email inboxes pinged across Origin Energy with a message from an alleged hacker who claimed to have accessed two million customer records.