Origin energy data breach…a salutory lesson ofwhat happens when you don’t respond quickly, candidly and coherently from the outset

July 27, 2026 |

The Origin energy data breach has been handled very badly by Origin to date.  That is not to say it has not been trying harder.  Often how an organisation responds in the first few days of a data breach sets the tone. That is certainly the experience in the United States.  Here the culture is less attuned to having a data breach recovery plan and there is less effort in wargaming what would happen if there is a data breach.

Origin put out a statement on Thursday which said not much of anything:

Origin Energy Limited (Origin) provides the following update on its data security incident.  

Origin can confirm there has been unauthorised access and disclosure of some customers’ data. 

We are working to understand the total number of impacted customers, and we will contact any customers where we can confirm they have been affected.  

For affected customers, impacted data may include name, address, date of birth, contact phone number and account information, as well as the last four digits of a credit card, or the last three digits of a bank account. Incomplete credit card or bank account information cannot be used to make purchases or access accounts. 

Origin CEO Frank Calabria said, “I’m sorry this has happened. Customers trust Origin with their information, and I apologise for the impact this may cause. 

“We are contacting affected customers, offering support and have set up a dedicated contact number and additional resources to help manage our response to this incident. 

“One of our key priorities is taking action to secure our systems and ensure no further unauthorised access. We are working with independent cyber experts to support Origin, and that work is continuing alongside the work of authorities,” Mr Calabria said. 

Origin continues to engage with Australian Government agencies, including the Australian Cyber Security Centre, the Australian Federal Police and the Office of the Australian Information Commissioner. 

It now admits there was a data breach rather than a “potential security incident” and says names, addresses, dates of birth, contact phone numbers and account information being leaked and the incomplete portions of credit cards and bank details were affected.  The rest is a word salad of platitudes and the usual boilerplate of working with government agencies. It is a sub par statement.

Meanwhile the media has filled in the gaps Origin can’t or won’t and speculates.  Cyber security Insiders reports with Origin Energy Sector Data Breach Widens to 5 Million Customers the flaws in Origins approach to date.  Insurance Business reports on a possible settlement by Origin with Origin silent on settlement as alleged fired employee breach detail emerges.  The Conversation has used the Origin breach as a learning experience with The Origin Energy breach has been unusual – but there are ways to better protect your data.

Origin’s stumbling, tentative and generally resistant approach to being open will not help when it is forced to provide more information.  And it will.

 

Leave a Reply