Origin now admits to cyber breach affect 900,000 after “initial review”. The dreadful response to this data breach continues
July 28, 2026 |
In my experience organisations that do not have a data breach response plan, which they test and rehearse, suffer for it when there is a data breach. Those organisations commonly resist engaging with the community, media or even government. That may suit some businesses but does not help when dealing with a data breach, where controlled transparency is a positive trait. If Origin had a data breach response plan it probably has it locked away in a safe and the board of directors have forgotten the combination.
A good data breach response plan has a list of tasks that need to be attended to and a a specified group of people who have specific tasks to do. It should also have contact details of experts to contact; technical, media, legal, human resources. There needs to be as much done in the first 24 hours as possible to set up a coherent response.
Origin’s response to this data breach has been uniformly dreadful. It’s initial response came when it was told there was a data breach. Then it was incredibly cagey and defensive. Then it was vague. Then there was a partial admission without identifying how many customers were affected. And today it provides an initial review, whatever that means, which identifies 900,000 customers, and former customers, affected. Could be as high as 20% of the customers. That is bound to be an understatement. What is difficult to square is why it is taking so long to get a good idea of the scope of the attack. As Origin says, it was aware of a “potential security threat” since early July and then on 22 July some new information indicated a “potential security incident“. It is so vague as to be meaningless. So there was no breach in early July? Or was there? If the threat was identified what was done so as to avoid an incident? Sometimes organisations think it is clever by to use vague terminology to say nothing but claim they are saying something. It rarely works as well as they think it might. Here it falls at the first hurdle. It makes little sense and begs more questions than it answers. Origin’s problems have been compounded by the fact that the hacker has engaged with the media, specifically the Australian. That happens occasionally but can be managed as well. Origin has not managed that side of things well either.
Something very odd is going on at Origin.
Today’s Origin statement provides:
Origin CEO Frank Calabria said:
“We have now completed the initial phase of our review into Origin’s customer data security incident.
“At this point in time, we believe the information of approximately 900,000 current and former customers was accessed.?
“To our customers, I am sorry. We don’t take for granted the trust customers place in Origin and our safeguarding of their information.
“Supporting affected customers is our key priority. We are contacting those customers whose information has been accessed and are providing support to them.
“We’ve extended our customer support hours and established a dedicated contact number for this incident.
“We are working with cyber security and forensic specialists to ensure the incident is contained, and we’ve taken a number of steps to secure our systems.
“We continue to work very closely with the Australian Government and other agencies, including the Australian Cyber Security Centre, the National Office of Cyber Security and the Australian Federal Police. We have also notified the Office of the Australian Information Commissioner.
“Our review into this incident is continuing,” Mr Calabria said.
What happened
“Since early July, Origin had been reviewing a potential security threat. We worked to confirm its credibility and potential impact; however, based on the information available, it was not assessed to be credible.
“On 22 July, new information emerged that indicated a potential security incident may have occurred. We acted immediately, providing updates to the market and notifying our customers as a precaution.
“Importantly, this is a criminal matter that is subject to an ongoing investigation by the relevant authorities, and given this, we are constrained by the level of information we can provide about the incident at this time,” Mr Calabria said.
Advice and support for customers
Origin has made specialist identity and cyber support services available to affected customers.
Customers with questions can contact us on our dedicated line on +61 8 9922 7000 for assistance or email us at hello@origin.com.au.
Further updates will also be available on this page.
We recommend all customers remain vigilant to suspicious activity and a heightened risk of scams:
-
- be cautious of unexpected calls, emails or text messages referring to your Origin account, and do not click on links in unsolicited messages;
-
- independently verify the identity of any caller by contacting Origin on a number available through official channels;
-
- do not provide your online account passwords to anyone, and do not?provide any personal or financial information unless you are certain of who you are dealing with; and
-
- where available, use two-step authentication (such as an authentication application) for personal email accounts and other online accounts.
“We are acutely aware that others may exploit this incident, including by impersonating Origin or through other scam activity.
“We recommend that all our customers remain vigilant to suspicious activity and a heightened risk of scams,” Mr Calabria said.
Not surprisingly the story has been run by the ABC, the AFR and Nine.com just to name a few.